Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - warriorsd

Pages: [1] 2
1
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 29, 2015, 09:15:04 PM »

All done! I followed your latest steps and I think its all running perfectly again :)


I cant thank you enough!!! Really appreciate your assistance.


Thanks again!



2
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 29, 2015, 01:35:50 AM »

I think youve done it!!! I have tried to do this for about 8 weeks. This is the first day I dont get an anoying ad from this stupid cloudscout thing! The main problem was always in my firefox browser. After reseting it just then as you have asked me to do above it seems to work!! \"smile.png\"


Is there anything I should do from here to make sure its really gone or do you think this nasty piece of spyware is finally gone?



3
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 28, 2015, 05:23:43 PM »

Hi guestolo


 


Please find below malwarebytes log. Unfortuanetly i still have this stupid ads by cloudscout crap hanging around ... :(


 


 


Malwarebytes Anti-Malware

www.malwarebytes.org


Scan Date: 29/08/2015

Scan Time: 7:35 AM

Logfile: log.txt

Administrator: Yes


Version: 2.1.8.1057

Malware Database: v2015.08.28.06

Rootkit Database: v2015.08.16.01

License: Free

Malware Protection: Disabled

Malicious Website Protection: Disabled

Self-protection: Disabled


OS: Windows 7 Service Pack 1

CPU: x64

File System: NTFS

User: Dell


Scan Type: Threat Scan

Result: Completed

Objects Scanned: 447737

Time Elapsed: 37 min, 31 sec


Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Enabled

PUM: Enabled


Processes: 0

(No malicious items detected)


Modules: 0

(No malicious items detected)


Registry Keys: 6

PUP.Optional.IdleCrawler.A, HKLM\\SOFTWARE\\MICROSOFT\\WINDOWS NT\\CURRENTVERSION\\SCHEDULE\\TASKCACHE\\TREE\\Runner IC, Delete-on-Reboot, [e94dc34b494238fea0c67ba7649f9d63],

PUM.Security.Hijack.DisableChromeUpdates, HKLM\\SOFTWARE\\POLICIES\\GOOGLE\\UPDATE, Quarantined, [6dc9937b2b60181e3c2120897094f808],

PUP.Optional.MindSpark.A, HKLM\\SOFTWARE\\WOW6432NODE\\MOZILLAPLUGINS\\@ei.InboxAce_1g.com/Plugin, Quarantined, [33030c02246777bf7760525421e3ad53],

PUM.Security.Hijack.DisableChromeUpdates, HKLM\\SOFTWARE\\WOW6432NODE\\POLICIES\\GOOGLE\\UPDATE, Quarantined, [5adcba54c9c28da9f76601a8c73d3cc4],

PUP.Optional.Spigot.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\SOFTWARE\\MICROSOFT\\INTERNET EXPLORER\\SEARCHSCOPES\\{2F64CDBE-8316-45BE-91CF-1CBBCEAE867C}, Quarantined, [54e263ab90fb290d3f0dcc5c5fa41ce4],

PUP.Optional.OneSystemCare.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1001\\SOFTWARE\\ONE SYSTEM CARE, Quarantined, [e2540707b8d3fd39e2c7f2be72924eb2],


Registry Values: 6

PUM.Security.Hijack.DisableChromeUpdates, HKLM\\SOFTWARE\\POLICIES\\GOOGLE\\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Quarantined, [6dc9937b2b60181e3c2120897094f808]

PUM.Security.Hijack.DisableChromeUpdates, HKLM\\SOFTWARE\\WOW6432NODE\\POLICIES\\GOOGLE\\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, Quarantined, [5adcba54c9c28da9f76601a8c73d3cc4]

PUP.Optional.Spigot.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\SOFTWARE\\MICROSOFT\\INTERNET EXPLORER\\SEARCHSCOPES\\{2F64CDBE-8316-45BE-91CF-1CBBCEAE867C}|URL, https://au.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p=\'>https://au.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}, Quarantined, [54e263ab90fb290d3f0dcc5c5fa41ce4]

PUP.Optional.OneSystemCare.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1001\\SOFTWARE\\ONE SYSTEM CARE|OSID, 6.1, Quarantined, [e2540707b8d3fd39e2c7f2be72924eb2]

PUP.Optional.OneSystemCare.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1001\\SOFTWARE\\ONE SYSTEM CARE|AdvertsLink1, http://dl.softservers.net/121002113/DriverPro.exe\'>http://dl.softservers.net/121002113/DriverPro.exe, Quarantined, [51e52ae4305b23135dee317835cf7b85]

PUP.Optional.OneSystemCare.A, HKU\\S-1-5-21-2799920661-1438349000-4008728122-1001\\SOFTWARE\\ONE SYSTEM CARE|AdvertsLink2, http://dl.softservers.net/171002113/LiveSupport.exe\'>http://dl.softservers.net/171002113/LiveSupport.exe, Quarantined, [d6600d014c3fca6cd07b4f5afe06629e]


Registry Data: 1

Trojan.DNSChanger, HKLM\\SYSTEM\\CURRENTCONTROLSET\\SERVICES\\TCPIP\\PARAMETERS\\Interfaces\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}|NameServer, 82.163.143.137,82.163.142.139, Good: (), Bad: (82.163.143.137,82.163.142.139),Replaced,[1a1ca668e5a684b2c90fd887d431be42]


Folders: 0

(No malicious items detected)


Files: 9

PUP.Optional.MultiPlug.A, C:\\ProgramData\\685268800007c57\\685268800007c57.dll, Quarantined, [dc5a44ca54373afce8b605cd4cb59967],

PUP.Optional.MultiPlug.A, C:\\Program Files (x86)\\WallButtress\\WallButtress.dll, Quarantined, [bd797e908308d1656539d9f9a859f60a],

PUP.Optional.InstallCore.SID.C, C:\\Users\\Dell\\Downloads\\Unconfirmed 599568.crdownload, Quarantined, [f83ef21ccfbc7cba66e792ff18ed25db],

PUP.Optional.InstallCore.SID.C, C:\\Users\\Dell\\Downloads\\Unconfirmed 159729.crdownload, Quarantined, [ba7c8886bfccd75f51fc0e83e91c21df],

PUP.Optional.InstallCore.A, C:\\Users\\Dell\\Downloads\\CR_Downloader_for_mame.exe, Quarantined, [9f97ff0f27642214df50e2cee51c659b],

PUP.Optional.InstallCore.A, C:\\Users\\Dell\\Downloads\\CR_Downloader_for_marvel-vs.-capcom--clash-of-super-heroes-(usa-980123).exe, Quarantined, [ac8a8e80652643f3e649a20e37ca32ce],

PUP.Optional.InstallCore.A, C:\\Users\\Dell\\Downloads\\CR_Downloader_for_project64.exe, Quarantined, [fe38ab6344470c2a131cd7d9fc0507f9],

PUP.Optional.InstallCore.A, C:\\Users\\Dell\\Downloads\\CR_Downloader_for_tekken-tag-tournament-(us,-teg3-ver.c1).exe, Quarantined, [91a5a46a692271c50827258b20e1ab55],

PUP.Optional.InstallCore.SID.C, C:\\Users\\Dell\\Downloads\\Unconfirmed 366261.crdownload, Quarantined, [a393b7578803300676d7078a9a6bab55],


Physical Sectors: 0

(No malicious items detected)



(end)



4
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 28, 2015, 06:48:10 AM »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:26-08-2015

Ran by Dell (administrator) on DELL-PC (28-08-2015 21:43:25)

Running from C:\\Users\\Dell\\Downloads

Loaded Profiles: Dell (Available Profiles: Dell & UpdatusUser)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: FF)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/\'>http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/


==================== Processes (Whitelisted) =================


(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)


(Microsoft Corporation) C:\\Program Files\\Microsoft Security Client\\MsMpEng.exe

(Intel Corporation) C:\\Windows\\System32\\hkcmd.exe

(Microsoft Corporation) C:\\Program Files\\Microsoft Security Client\\NisSrv.exe

(Microsoft Corporation) C:\\Windows\\SysWOW64\\wbem\\WmiPrvSE.exe

(Intel Corporation) C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

(Microsoft Corporation) C:\\Windows\\System32\\PrintIsolationHost.exe

(SUPERAntiSpyware.com) C:\\Program Files\\SUPERAntiSpyware\\SASCore64.exe

(Intel(R) Corporation) C:\\Program Files\\Intel\\BluetoothHS\\BTHSSecurityMgr.exe

(Microsoft Corp.) C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLIDSVC.EXE

(Microsoft Corp.) C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLIDSVCM.EXE

(Intel Corporation) C:\\Program Files\\Intel\\BluetoothHS\\BTHSAmpPalService.exe

(Apple Inc.) C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe

(Microsoft Corporation) C:\\Windows\\SysWOW64\\notepad.exe

(OldTimer Tools) C:\\Users\\Dell\\Downloads\\TFC.exe

(TeamViewer GmbH) C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe

(Mozilla Corporation) C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe

(Microsoft Corporation) C:\\Windows\\System32\\dllhost.exe

(Microsoft Corporation) C:\\Windows\\System32\\dllhost.exe



==================== Registry (Whitelisted) ===========================


(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)


HKLM\\...\\Run: [IntelPAN] => C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\iFrmewrk.exe [1935120 2011-07-27] (Intel(R) Corporation)

HKLM\\...\\Run: [NVHotkey] => rundll32.exe C:\\Windows\\system32\\nvHotkey.dll,Start

HKLM\\...\\Run: [MSC] => c:\\Program Files\\Microsoft Security Client\\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)

HKLM\\...\\Run: [CDAServer] => C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe [462712 2012-03-09] ()

HKLM\\...\\Run: [AdobeAAMUpdater-1.0] => C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe [557768 2014-10-14] (Adobe Systems Incorporated)

HKLM\\...\\Run: [XboxStat] => C:\\Program Files\\Microsoft Xbox 360 Accessories\\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)

HKLM-x32\\...\\Run: [BCSSync] => C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)

HKLM-x32\\...\\Run: [Dell Webcam Central] => C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd)

HKLM-x32\\...\\Run: [KiesTrayAgent] => C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)

HKLM-x32\\...\\Run: [HP Software Update] => C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)

HKLM-x32\\...\\Run: [HP Component Manager] => C:\\Program Files (x86)\\HP\\hpcoretech\\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)

HKLM-x32\\...\\Run: [QuickTime Task] => C:\\Program Files (x86)\\QuickTime\\QTTask.exe [421888 2014-10-02] (Apple Inc.)

HKLM-x32\\...\\Run: [Dropbox] => C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe [39179912 2015-08-06] (Dropbox, Inc.)

Winlogon\\Notify\\igfxcui: C:\\Windows\\system32\\igfxdev.dll (Intel Corporation)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [AdobeBridge] => [X]

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [Cloud Sync Application] => C:\\Program Files (x86)\\Renewed Vision\\ProPresenter 5\\CloudSyncApp.exe [169984 2014-01-27] (Renewed Vision, Inc)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [Facebook Update] => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe [138096 2014-07-26] (Facebook Inc.)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [KiesPreload] => C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe [1562264 2014-07-25] (Samsung)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [KiesAirMessage] => C:\\Program Files (x86)\\Samsung\\Kies\\KiesAirMessage.exe -startup

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [CCleaner Monitoring] => C:\\Program Files\\CCleaner\\CCleaner64.exe [8358680 2015-06-02] (Piriform Ltd)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [SUPERAntiSpyware] => C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe [7930136 2015-07-31] (SUPERAntiSpyware)

AppInit_DLLs-x32: c:\\windows\\syswow64\\nvinit.dll => c:\\windows\\syswow64\\nvinit.dll [193128 2011-04-22] (NVIDIA Corporation)

ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

CHR HKLM\\SOFTWARE\\Policies\\Google: Policy restriction <======= ATTENTION


==================== Internet (Whitelisted) ====================


(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)










HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =

SearchScopes: HKU\\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =



Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

Tcpip\\Parameters: [DhcpNameServer] 192.168.0.1

Tcpip\\..\\Interfaces\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}: [NameServer] 82.163.143.137,82.163.142.139

Tcpip\\..\\Interfaces\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}: [DhcpNameServer] 192.168.0.1

Tcpip\\..\\Interfaces\\{BF7548A4-4B37-4112-B6B7-87AD8793FEF1}: [DhcpNameServer] 172.20.10.1


FireFox:

========

FF ProfilePath: C:\\Users\\Dell\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\9zk16fkx.default-1438300192999

FF Plugin: @adobe.com/FlashPlayer -> C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_18_0_0_232.dll [2015-08-12] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files\\Microsoft Silverlight\\5.1.30214.0\\npctrl.dll [2014-02-13] ( Microsoft Corporation)

FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\Utils\\npAdobeAAMDetect64.dll [2014-10-15] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_18_0_0_232.dll [2015-08-12] ()

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\\Program Files (x86)\\iTunes\\Mozilla Plugins\\npitunes.dll [2014-10-30] ()

FF Plugin-x32: @ei.InboxAce_1g.com/Plugin -> C:\\Program Files (x86)\\InboxAce_1gEI\\Installr\\1.bin\\NP1gEISB.dll [No File]

FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files (x86)\\Microsoft Silverlight\\5.1.30214.0\\npctrl.dll [2014-02-13] ( Microsoft Corporation)

FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll [2012-09-12] (Microsoft Corporation)

FF Plugin-x32: @nvidia.com/3DVision -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll [2011-04-21] (NVIDIA Corporation)

FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll [2011-04-21] (NVIDIA Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.1\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.1\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\\Program Files (x86)\\VideoLAN\\VLC\\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\\Program Files (x86)\\Adobe\\Reader 11.0\\Reader\\AIR\\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\Utils\\npAdobeAAMDetect32.dll [2014-10-15] (Adobe Systems)

FF Plugin HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000: @hola.org/vlc,version=1.8.204 -> C:\\Users\\Dell\\AppData\\Local\\Hola\\firefox\\app\\vlc No File

FF Plugin HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\\Users\\Dell\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)

FF HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Firefox\\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\\ProgramData\\McAfee Security Scan\\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi

FF Extension: McAfee Security Scan Plus - C:\\ProgramData\\McAfee Security Scan\\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]


Chrome:

=======

CHR dev: Chrome dev build detected! <======= ATTENTION

CHR Profile: C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default

CHR Extension: (Chrome Hotword Shared Module) - C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lccekmodgklaepjeofjdjpbminllajkg [2015-07-11]

CHR Extension: (Chrome Web Store Payments) - C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-11]


==================== Services (Whitelisted) ========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R2 !SASCORE; C:\\Program Files\\SUPERAntiSpyware\\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)

R2 Apple Mobile Device Service; C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)

S2 dbupdate; C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [134512 2015-07-06] (Dropbox, Inc.)

S3 dbupdatem; C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [134512 2015-07-06] (Dropbox, Inc.)

S2 Ds3Service; C:\\Program Files\\Scarlet.Crush Productions\\bin\\ScpService.exe [388352 2013-05-05] (Scarlet.Crush Productions)

S2 HPSupportSolutionsFrameworkService; C:\\Program Files (x86)\\Hp\\Common\\HPSupportSolutionsFrameworkService.exe [89352 2014-09-15] (Hewlett-Packard Company)

S3 McComponentHostService; C:\\Program Files\\McAfee Security Scan\\3.8.150\\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)

R2 MsMpSvc; c:\\Program Files\\Microsoft Security Client\\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)

S3 MyWiFiDHCPDNS; C:\\Program Files\\Intel\\WiFi\\bin\\PanDhcpDns.exe [340240 2011-07-27] ()

R3 NisSrv; c:\\Program Files\\Microsoft Security Client\\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)

S3 SwitchBoard; C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

R2 TeamViewer; C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)

S3 WinDefend; C:\\Program Files\\Windows Defender\\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

S3 aspnet_state; %SystemRoot%\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe [X]

S2 HPSLPSVC; C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS595E\\hpslpsvc64.dll [X]


===================== Drivers (Whitelisted) ==========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R0 MpFilter; C:\\Windows\\System32\\DRIVERS\\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)

R2 NisDrv; C:\\Windows\\System32\\DRIVERS\\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)

R1 SASDIFSV; C:\\Program Files\\SUPERAntiSpyware\\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

R1 SASKUTIL; C:\\Program Files\\SUPERAntiSpyware\\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

R3 ScpVBus; C:\\Windows\\System32\\DRIVERS\\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)

S3 MBAMSwissArmy; \\??\\C:\\Windows\\system32\\drivers\\MBAMSwissArmy.sys [X]


==================== NetSvcs (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== One Month Created files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2015-08-28 21:39 - 2015-08-28 21:39 - 00448512 _____ (OldTimer Tools) C:\\Users\\Dell\\Downloads\\TFC.exe

2015-08-28 21:37 - 2015-08-28 21:37 - 00001537 _____ C:\\Users\\Dell\\Desktop\\JRT.txt

2015-08-28 21:24 - 2015-08-28 21:24 - 01792178 _____ (Malwarebytes Corporation) C:\\Users\\Dell\\Downloads\\JRT.exe

2015-08-28 21:23 - 2015-08-28 21:23 - 01618432 _____ C:\\Users\\Dell\\Downloads\\AdwCleaner.exe

2015-08-27 22:53 - 2015-08-27 22:53 - 00048626 _____ C:\\Users\\Dell\\Downloads\\Addition.txt

2015-08-27 22:52 - 2015-08-28 21:43 - 00018052 _____ C:\\Users\\Dell\\Downloads\\FRST.txt

2015-08-27 22:52 - 2015-08-28 21:43 - 00000000 ____D C:\\FRST

2015-08-27 22:52 - 2015-08-27 22:52 - 02186752 _____ (Farbar) C:\\Users\\Dell\\Downloads\\FRST64.exe

2015-08-27 22:43 - 2015-08-27 22:43 - 00011145 _____ C:\\Users\\Dell\\Downloads\\hijackthis.log

2015-08-27 22:42 - 2015-08-27 22:42 - 00388608 _____ (Trend Micro Inc.) C:\\Users\\Dell\\Downloads\\HijackThis.exe

2015-08-23 23:30 - 2015-08-23 23:30 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Skype

2015-08-23 07:22 - 2015-08-23 07:22 - 00112093 _____ C:\\Users\\Dell\\Downloads\\Esther.pptx

2015-08-22 14:22 - 2015-08-22 14:22 - 00001870 _____ C:\\Users\\Dell\\Downloads\\Come Praise & Glorify (Bob Kauflin, Tim Chester).xml

2015-08-22 14:22 - 2015-08-22 14:22 - 00001792 _____ C:\\Users\\Dell\\Downloads\\Here is Love (Matt Redman, William Rees, Robert Lowry).xml

2015-08-22 14:16 - 2015-08-22 14:16 - 00001813 _____ C:\\Users\\Dell\\Downloads\\It Is Well With My Soul (Philipp Bliss, Horatio G Spafford).xml

2015-08-20 23:58 - 2015-08-23 07:31 - 00000000 ____D C:\\Program Files\\Sublime Text 3

2015-08-20 23:58 - 2015-08-20 23:58 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\Sublime Text 3

2015-08-20 23:58 - 2015-08-20 23:58 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Sublime Text 3

2015-08-20 18:18 - 2015-08-20 22:00 - 00000000 ____D C:\\Users\\Dell\\Downloads\\dmps

2015-08-15 21:09 - 2015-08-15 21:09 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Dropbox

2015-07-31 10:13 - 2015-07-31 10:13 - 00000000 ____D C:\\SUPERDelete

2015-07-31 10:12 - 2015-08-23 07:31 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\SUPERAntiSpyware

2015-07-31 10:12 - 2015-08-23 07:31 - 00000000 ____D C:\\Program Files\\SUPERAntiSpyware

2015-07-31 10:12 - 2015-07-31 10:12 - 00001808 _____ C:\\Users\\Public\\Desktop\\SUPERAntiSpyware Professional.lnk

2015-07-31 10:12 - 2015-07-31 10:12 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\SUPERAntiSpyware.com

2015-07-31 10:12 - 2015-07-31 10:12 - 00000000 ____D C:\\ProgramData\\SUPERAntiSpyware.com

2015-07-31 10:09 - 2015-07-31 10:12 - 22854032 _____ (SUPERAntiSpyware) C:\\Users\\Dell\\Downloads\\SUPERAntiSpywarePro.exe


==================== One Month Modified files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2015-08-28 21:44 - 2014-03-13 19:22 - 00000072 _____ C:\\Users\\Public\\LMDebug.log

2015-08-28 21:41 - 2009-07-14 14:45 - 00021472 ____H C:\\Windows\\system32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2015-08-28 21:41 - 2009-07-14 14:45 - 00021472 ____H C:\\Windows\\system32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2015-08-28 21:40 - 2012-10-29 20:51 - 02095631 _____ C:\\Windows\\WindowsUpdate.log

2015-08-28 21:30 - 2015-07-06 17:38 - 00000000 ___RD C:\\Users\\Dell\\Dropbox

2015-08-28 21:30 - 2015-07-06 17:36 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Dropbox

2015-08-28 21:29 - 2012-11-04 12:18 - 00000830 _____ C:\\Windows\\Tasks\\Adobe Flash Player Updater.job

2015-08-28 21:29 - 2012-10-29 21:23 - 00000000 ____D C:\\ProgramData\\NVIDIA

2015-08-28 21:28 - 2015-07-06 17:36 - 00000900 _____ C:\\Windows\\Tasks\\DropboxUpdateTaskMachineCore.job

2015-08-28 21:28 - 2015-06-28 11:25 - 00004302 _____ C:\\Windows\\setupact.log

2015-08-28 21:28 - 2015-04-07 16:42 - 00000894 _____ C:\\Windows\\Tasks\\GoogleUpdateTaskMachineCore.job

2015-08-28 21:28 - 2009-07-14 15:08 - 00000006 ____H C:\\Windows\\Tasks\\SA.DAT

2015-08-28 21:27 - 2015-04-06 14:59 - 00000000 ____D C:\\AdwCleaner

2015-08-28 21:01 - 2015-04-07 16:42 - 00000898 _____ C:\\Windows\\Tasks\\GoogleUpdateTaskMachineUA.job

2015-08-28 20:48 - 2015-07-06 17:36 - 00000904 _____ C:\\Windows\\Tasks\\DropboxUpdateTaskMachineUA.job

2015-08-28 20:41 - 2014-08-26 18:11 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Adobe

2015-08-28 19:29 - 2014-07-26 22:24 - 00000924 _____ C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000UA.job

2015-08-27 22:29 - 2014-07-26 22:24 - 00000902 _____ C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000Core.job

2015-08-27 22:21 - 2012-12-02 20:27 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\Skype

2015-08-24 00:04 - 2015-04-07 16:43 - 00002183 _____ C:\\Users\\Public\\Desktop\\Google Chrome.lnk

2015-08-23 23:30 - 2014-11-30 18:07 - 00000000 ___RD C:\\Program Files (x86)\\Skype

2015-08-23 23:30 - 2014-05-26 17:08 - 00002697 _____ C:\\Users\\Public\\Desktop\\Skype.lnk

2015-08-23 23:30 - 2012-12-02 20:26 - 00000000 ____D C:\\ProgramData\\Skype

2015-08-23 17:45 - 2015-05-01 12:25 - 00000000 ____D C:\\Users\\Dell\\Desktop\\M&M Website

2015-08-23 07:31 - 2015-07-11 10:29 - 00000000 ____D C:\\Program Files (x86)\\Mozilla Firefox

2015-08-23 07:31 - 2015-04-07 16:43 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Google Chrome

2015-08-23 07:31 - 2012-11-24 18:20 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\uTorrent

2015-08-23 07:31 - 2012-10-31 17:16 - 00000000 ____D C:\\Program Files (x86)\\Mozilla Maintenance Service

2015-08-23 07:31 - 2009-07-14 13:20 - 00000000 ____D C:\\Windows\\registration

2015-08-23 07:31 - 2009-07-14 13:20 - 00000000 ____D C:\\Windows\\AppCompat

2015-08-22 13:55 - 2009-07-14 15:13 - 00796054 _____ C:\\Windows\\system32\\PerfStringBackup.INI

2015-08-22 13:37 - 2015-06-13 18:21 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\vlc

2015-08-22 13:33 - 2012-10-29 20:51 - 00000000 ____D C:\\Users\\Dell

2015-08-16 16:39 - 2015-07-12 14:23 - 00004104 _____ C:\\Windows\\PFRO.log

2015-08-15 21:09 - 2015-07-06 17:24 - 00000000 ____D C:\\Program Files (x86)\\Dropbox

2015-08-12 20:29 - 2012-11-04 12:18 - 00778440 _____ (Adobe Systems Incorporated) C:\\Windows\\SysWOW64\\FlashPlayerApp.exe

2015-08-12 20:29 - 2012-11-04 12:18 - 00142536 _____ (Adobe Systems Incorporated) C:\\Windows\\SysWOW64\\FlashPlayerCPLApp.cpl

2015-08-12 20:29 - 2012-11-04 12:18 - 00003768 _____ C:\\Windows\\System32\\Tasks\\Adobe Flash Player Updater

2015-08-08 11:40 - 2012-10-29 20:59 - 00000000 ____D C:\\Users\\Dell\\Desktop\\N5110

2015-07-31 10:06 - 2015-06-28 10:37 - 00000000 ____D C:\\Program Files\\CCleaner

2015-07-31 09:49 - 2015-06-11 17:16 - 00000000 ____D C:\\Users\\Dell\\Desktop\\Old Firefox Data


==================== Files in the root of some directories =======


2014-12-06 08:09 - 2014-12-07 19:57 - 1019904 _____ () C:\\Users\\Dell\\AppData\\Roaming\\123 Cheese Prefsv3

2013-01-06 08:57 - 2013-01-06 08:57 - 0000132 _____ () C:\\Users\\Dell\\AppData\\Roaming\\Adobe PNG Format CS5 Prefs

2013-06-30 12:13 - 2008-07-07 13:22 - 0000014 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options.ini

2013-06-30 12:13 - 2012-07-07 13:04 - 0000003 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options_pdfcombine.ini

2013-06-30 12:13 - 2013-02-23 12:15 - 0000003 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options_pdfrotator.ini

2013-06-30 12:13 - 2013-06-30 12:14 - 0000703 _____ () C:\\Users\\Dell\\AppData\\Roaming\\pdfsound.dll

2013-06-30 12:13 - 2013-06-09 09:38 - 0000053 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setting.ini

2013-06-30 12:13 - 2013-06-08 13:43 - 0000030 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup.ini

2013-06-30 12:13 - 2013-06-09 09:30 - 0000043 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup_pdfcombine.ini

2013-06-30 12:13 - 2013-06-09 10:34 - 0000043 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup_pdfrotator.ini

2015-04-03 17:12 - 2015-04-04 03:42 - 0000062 _____ () C:\\Users\\Dell\\AppData\\Roaming\\WB.CFG

2015-02-05 18:59 - 2015-02-05 19:04 - 0000600 _____ () C:\\Users\\Dell\\AppData\\Roaming\\winscp.rnd

2014-12-06 08:25 - 2015-06-14 18:55 - 0109925 _____ () C:\\Users\\Dell\\AppData\\Local\\ars.cache

2014-12-06 08:25 - 2015-06-14 18:55 - 0468633 _____ () C:\\Users\\Dell\\AppData\\Local\\census.cache

2014-10-11 19:24 - 2014-10-11 19:24 - 0000092 _____ () C:\\Users\\Dell\\AppData\\Local\\fusioncache.dat

2014-12-06 07:58 - 2014-12-06 07:58 - 0000036 _____ () C:\\Users\\Dell\\AppData\\Local\\housecall.guid.cache

2013-02-19 19:01 - 2015-02-05 18:46 - 0000600 _____ () C:\\Users\\Dell\\AppData\\Local\\PUTTY.RND

2015-04-06 14:56 - 2015-04-06 14:57 - 0011722 _____ () C:\\Users\\Dell\\AppData\\Local\\Temp-log.txt

2014-10-10 17:56 - 2014-10-10 18:14 - 0000372 _____ () C:\\ProgramData\\hpzinstall.log


==================== Bamital & volsnap =================


(There is no automatic fix for files that do not pass verification.)


C:\\Windows\\system32\\winlogon.exe => File is digitally signed

C:\\Windows\\system32\\wininit.exe => File is digitally signed

C:\\Windows\\SysWOW64\\wininit.exe => File is digitally signed

C:\\Windows\\explorer.exe => File is digitally signed

C:\\Windows\\SysWOW64\\explorer.exe => File is digitally signed

C:\\Windows\\system32\\svchost.exe => File is digitally signed

C:\\Windows\\SysWOW64\\svchost.exe => File is digitally signed

C:\\Windows\\system32\\services.exe => File is digitally signed

C:\\Windows\\system32\\User32.dll => File is digitally signed

C:\\Windows\\SysWOW64\\User32.dll => File is digitally signed

C:\\Windows\\system32\\userinit.exe => File is digitally signed

C:\\Windows\\SysWOW64\\userinit.exe => File is digitally signed

C:\\Windows\\system32\\rpcss.dll => File is digitally signed

C:\\Windows\\system32\\dnsapi.dll => File is digitally signed

C:\\Windows\\SysWOW64\\dnsapi.dll => File is digitally signed

C:\\Windows\\system32\\Drivers\\volsnap.sys => File is digitally signed



LastRegBack: 2015-08-23 18:27


==================== End of FRST.txt ============================



5
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 28, 2015, 06:46:48 AM »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Malwarebytes

Version: 7.5.9 (08.27.2015:1)

OS: Windows 7 Home Premium x64

Ran by Dell on Fri 28/08/2015 at 21:33:32.23

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





~~~ Services




~~~ Tasks


Successfully deleted: [Task] C:\\Windows\\system32\\tasks\\ProPCCleaner_Popup

Successfully deleted: [Task] C:\\Windows\\system32\\tasks\\ProPCCleaner_Start




~~~ Registry Values




~~~ Registry Keys




~~~ Files




~~~ Folders


Successfully deleted: [Empty Folder] C:\\Users\\Dell\\Appdata\\Local\\{AFFE82F4-CECE-C465-0DA5-151AEBFFBC8B}

Successfully deleted: [Folder] C:\\Program Files (x86)\\myfree codec




~~~ FireFox


Emptied folder: C:\\Users\\Dell\\AppData\\Roaming\\mozilla\\firefox\\profiles\\9zk16fkx.default-1438300192999\\minidumps [2 files]




~~~ Chrome



[C:\\Users\\Dell\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Preferences] - default search provider reset


[C:\\Users\\Dell\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Preferences] - Extensions Deleted:


[C:\\Users\\Dell\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Secure Preferences] - default search provider reset


[C:\\Users\\Dell\\Appdata\\Local\\Google\\Chrome\\User Data\\Default\\Secure Preferences] - Extensions Deleted:

[]






~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Fri 28/08/2015 at 21:37:33.58

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 



6
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 28, 2015, 06:45:42 AM »

Hi guestolo


Thank you so much for your quick response. I have followed the instructions you have given, please find below the log files:


 


# AdwCleaner v5.004 - Logfile created 28/08/2015 at 21:27:33

# Updated 26/08/2015 by Xplode

# Database : 2015-08-25.1 [Server]

# Operating system : Windows 7 Home Premium Service Pack 1 (x64)

# Username : Dell - DELL-PC

# Running from : C:\\Users\\Dell\\Downloads\\AdwCleaner.exe

# Option : Cleaning

# Support : http://toolslib.net/forum\'>http://toolslib.net/forum


***** [ Services ] *****



***** [ Folders ] *****


[-] Folder Deleted : C:\\Program Files (x86)\\GreenTree Applications

[-] Folder Deleted : C:\\ProgramData\\ytd video downloader

[-] Folder Deleted : C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\ytd video downloader


***** [ Files ] *****


[-] File Deleted : C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_pstatic.bestpriceninja.com_0.localstorage

[-] File Deleted : C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal

[-] File Deleted : C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxps_pstatic.bestpriceninja.com_0.localstorage

[-] File Deleted : C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxps_pstatic.bestpriceninja.com_0.localstorage-journal

[-] File Deleted : C:\\Users\\Public\\Desktop\\YTD Video Downloader.lnk


***** [ Shortcuts ] *****



***** [ Scheduled tasks ] *****



***** [ Registry ] *****


[-] Key Deleted : HKLM\\SOFTWARE\\Classes\\TypeLib\\{198404EB-B6A6-447F-9D86-33F2FA3BC77F}

[-] Value Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ext\\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]

[-] Key Deleted : HKU\\.DEFAULT\\Software\\AppDataLow\\{1146AC44-2F03-4431-B4FD-889BC837521F}

[-] Key Deleted : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}


***** [ Web browsers ] *****



*************************


:: Winsock settings cleared


########## EOF - C:\\AdwCleaner\\AdwCleaner[C5].txt - [1915 bytes] ##########

 



7
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 27, 2015, 07:56:43 AM »

And here is the second Farbar log


 


Additional scan result of Farbar Recovery Scan Tool (x64) Version:26-08-2015

Ran by Dell (2015-08-27 22:53:31)

Running from C:\\Users\\Dell\\Downloads

Boot Mode: Normal

==========================================================



==================== Accounts: =============================


Administrator (S-1-5-21-2799920661-1438349000-4008728122-500 - Administrator - Disabled)

ASPNET (S-1-5-21-2799920661-1438349000-4008728122-1005 - Limited - Enabled)

Dell (S-1-5-21-2799920661-1438349000-4008728122-1000 - Administrator - Enabled) => C:\\Users\\Dell

Guest (S-1-5-21-2799920661-1438349000-4008728122-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-2799920661-1438349000-4008728122-1003 - Limited - Enabled)

UpdatusUser (S-1-5-21-2799920661-1438349000-4008728122-1001 - Limited - Enabled) => C:\\Users\\UpdatusUser


==================== Security Center ========================


(If an entry is included in the fixlist, it will be removed.)


AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}


==================== Installed Programs ======================


(Only the adware programs with \"Hidden\" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)


µTorrent (HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\uTorrent) (Version: 3.4.3.40760 - BitTorrent Inc.)

7-Zip 9.20 (x64 edition) (HKLM\\...\\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)

Adobe AIR (HKLM-x32\\...\\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)

Adobe Creative Cloud (HKLM-x32\\...\\Adobe Creative Cloud) (Version: 2.8.1.451 - Adobe Systems Incorporated)

Adobe Flash Player 18 ActiveX (HKLM-x32\\...\\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)

Adobe Flash Player 18 NPAPI (HKLM-x32\\...\\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)

Adobe Help Manager (HKLM-x32\\...\\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)

Adobe InDesign CC 2014 (HKLM-x32\\...\\{CCDCB9C4-72BA-1014-A3F8-D123F2F18BC2}) (Version: 10.1.0.070 - Adobe Systems Incorporated)

Adobe Media Player (HKLM-x32\\...\\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)

Adobe Reader XI (HKLM-x32\\...\\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)

Adobe® Content Viewer (HKLM-x32\\...\\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)

Advanced Audio FX Engine (HKLM-x32\\...\\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)

AiO_Scan (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

AiOSoftware (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

AirParrot (HKLM\\...\\{6C4958DF-4B1A-4290-947B-5F6AFDC74398}) (Version: 1.1.3 - Squirrels)

Apple Application Support (32-bit) (HKLM-x32\\...\\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\\...\\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)

Apple Mobile Device Support (HKLM\\...\\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)

Apple Software Update (HKLM-x32\\...\\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)

bl (x32 Version: 1.0.0 - Your Company Name) Hidden

Bonjour (HKLM\\...\\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)

Bonjour Print Services (HKLM\\...\\{4CE925AF-6519-4FEB-BEBD-DE2BFE2944EB}) (Version: 2.0.0.36 - Apple Inc.)

BufferChm (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

CCleaner (HKLM\\...\\CCleaner) (Version: 5.07 - Piriform)

Common Desktop Agent (Version: 1.62.0 - OEM) Hidden

Copy (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

CreativeProjects (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

CreativeProjectsTemplates (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

CueTour (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden

Dell Webcam Central (HKLM-x32\\...\\Dell Webcam Central) (Version: 1.40.05 - Creative Technology Ltd)

Destinations (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

Director (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

DocProc (x32 Version: 4.0.0.0 - Hewlett-Packard) Hidden

DocumentViewer (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

Dropbox (HKLM-x32\\...\\Dropbox) (Version: 3.8.6 - Dropbox, Inc.)

Dropbox Setup (HKLM-x32\\...\\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 1.0.0.5 - Dropbox, Inc.)

Dropbox Update Helper (x32 Version: 1.3.27.33 - Dropbox, Inc.) Hidden

Facebook Video Calling 3.1.0.521 (HKLM-x32\\...\\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)

Fax (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

FileZilla Client 3.6.0.2 (HKLM-x32\\...\\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project)

Google Chrome (HKLM-x32\\...\\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)

Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden

HandBrake 0.9.8 (HKLM-x32\\...\\HandBrake) (Version: 0.9.8 - )

HP Image Zone 4.2 (HKLM-x32\\...\\HP Photo & Imaging) (Version: 4.2 - HP)

HP PSC & OfficeJet 4.2 (HKLM-x32\\...\\{A1062847-0846-427A-92A1-BB8251A91E91}) (Version:  - HP)

HP Software Update (HKLM-x32\\...\\{457791C5-D702-4143-A7B2-2744BE9573F2}) (Version: 2.0.39.20040212 - Hewlett-Packard)

HP Support Solutions Framework (HKLM-x32\\...\\{44157EB3-D8D0-4BB1-B0F5-AD2C38814ED1}) (Version: 11.51.0027 - Hewlett-Packard Company)

HPSystemDiagnostics (x32 Version: 1.5.0.0 - Your Company Name) Hidden

Idle Crawler (HKLM-x32\\...\\04BE9A43-6885-2A4A-AF4C-8D81F5D1D303) (Version: 120.0.0.467 - MILE 27 LTD) <==== ATTENTION

InstantShare (x32 Version: 4.0.0.40 - Hewlett-Packard) Hidden

Intel PROSet Wireless (x32 Version:  - ) Hidden

Intel(R) Management Engine Components (HKLM-x32\\...\\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)

Intel(R) Processor Graphics (HKLM-x32\\...\\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation)

Intel(R) PROSet/Wireless WiFi Software (HKLM\\...\\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation)

iTunes (HKLM\\...\\{93F2A022-6C37-48B8-B241-FFABD9F60C30}) (Version: 12.1.2.27 - Apple Inc.)

Java 7 Update 65 (HKLM-x32\\...\\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.650 - Oracle)

KiwiG PhonTunes (HKLM-x32\\...\\KiwiG PhonTunes_is1) (Version:  - KiwiGeeker)

K-Lite Mega Codec Pack 11.2.0 (HKLM-x32\\...\\KLiteCodecPack_is1) (Version: 11.2.0 - )

Live! Cam Avatar Creator (HKLM-x32\\...\\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.3009.1 - Creative Technology Ltd)

McAfee Security Scan Plus (HKLM\\...\\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)

Microsoft .NET Framework 1.1 (HKLM-x32\\...\\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)

Microsoft .NET Framework 4.5.1 (HKLM\\...\\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)

Microsoft Office Professional Plus 2010 (HKLM-x32\\...\\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)

Microsoft Security Essentials (HKLM\\...\\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation)

Microsoft Silverlight (HKLM\\...\\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)

Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\\...\\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\\...\\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\\...\\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\\...\\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\\...\\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\\...\\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\\...\\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\\...\\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\\...\\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\\...\\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\\...\\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\\...\\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\\...\\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\\...\\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\\...\\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\\...\\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\\...\\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Xbox 360 Accessories 1.2 (HKLM\\...\\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)

Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

Mozilla Firefox 39.0 (x86 en-US) (HKLM-x32\\...\\Mozilla Firefox 39.0 (x86 en-US)) (Version: 39.0 - Mozilla)

Mozilla Maintenance Service (HKLM-x32\\...\\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)

MyFreeCodec (HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\MyFreeCodec) (Version:  - )

NavDesk 7.50 (HKLM-x32\\...\\{AB756389-9A03-44f3-ABAF-3699C01B4868}-Navman-7.50) (Version: 7.50.0109.128 - Navman Technology NZ Limited)

nito Installer (HKLM-x32\\...\\nito Installer) (Version: 01.00.00.00 - JailbreakAppleTV)

NVIDIA 3D Vision Driver 268.30 (HKLM\\...\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 268.30 - NVIDIA Corporation)

NVIDIA Graphics Driver 268.30 (HKLM\\...\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.30 - NVIDIA Corporation)

NVIDIA HD Audio Driver 1.2.22.1 (HKLM\\...\\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.2.22.1 - NVIDIA Corporation)

Overland (x32 Version: 2.1.5 - Hewlett-Packard) Hidden

PDFZilla V3.0.0 (HKLM-x32\\...\\PDFZilla_is1) (Version:  - PDFZilla, Inc.)

ph (x32 Version: 1.0.0 - Your Company Name) Hidden

PhotoGallery (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

PrintScreen (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

ProductContext (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

ProPresenter 5 (HKLM-x32\\...\\{5298EDD6-CB08-4F2A-8FFF-F9FDC3D815EB}) (Version: 5.2.401 - Renewed Vision)

ProPresenter 5 (HKLM-x32\\...\\{ABB004D0-D826-42CD-B299-8E5C91C6FCCE}) (Version: 5.1.500 - Renewed Vision)

PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden

QFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden

QuickProjects (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

QuickTime 7 (HKLM-x32\\...\\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)

Readme (x32 Version: 43.0.217.000 - Hewlett-Packard) Hidden

Realtek Ethernet Controller Driver (HKLM-x32\\...\\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)

Realtek USB 2.0 Card Reader (HKLM-x32\\...\\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)

Samsung CLP-360 Series (HKLM-x32\\...\\Samsung CLP-360 Series) (Version: 1.11 (24/10/2013) - Samsung Electronics Co., Ltd.)

Samsung Easy Printer Manager (HKLM-x32\\...\\Samsung Easy Printer Manager) (Version: 1.03.17.00(12/04/2013) - Samsung Electronics Co., Ltd.)

Samsung Easy Wireless Setup (HKLM-x32\\...\\Easy Wireless Setup) (Version: 3.70.5.0 - Samsung Electronics Co., Ltd.)

Samsung Kies (HKLM-x32\\...\\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.2.14014_7 - Samsung Electronics Co., Ltd.)

Samsung Kies (x32 Version: 2.6.2.14014_7 - Samsung Electronics Co., Ltd.) Hidden

Samsung Printer Diagnostics (HKLM-x32\\...\\Samsung Printer Diagnostics) (Version: 1.0.1.6.11 - Samsung Electronics Co., Ltd.)

Samsung Printer Live Update (HKLM-x32\\...\\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)

SAMSUNG USB Driver for Mobile Phones (HKLM\\...\\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)

Scan (x32 Version: 4.1.0.0 - Hewlett-Packard) Hidden

SDFormatter (HKLM-x32\\...\\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)

SkinsHP1 (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

Skype™ 7.8 (HKLM-x32\\...\\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)

SUPERAntiSpyware (HKLM\\...\\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1204 - SUPERAntiSpyware.com)

TeamViewer 10 (HKLM-x32\\...\\TeamViewer) (Version: 10.0.43879 - TeamViewer)

TI USB 3.0 Host Controller Driver (HKLM-x32\\...\\InstallShield_{B1EB7FFF-6E44-43D8-869D-B78E44CD3E0F}) (Version: 1.12.14.0 - Texas Instruments Inc.)

TI USB3 Host Driver (x32 Version: 1.12.14.0 - Texas Instruments Inc.) Hidden

TrayApp (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

Unload (x32 Version: 4.0.0 - Hewlett-Packard) Hidden

View User\'s Guide (HKLM-x32\\...\\View User Guide) (Version: 3.60.02.0 - )

VLC media player (HKLM-x32\\...\\VLC media player) (Version: 2.2.1 - VideoLAN)

VUDU To Go (HKLM-x32\\...\\com.vudu.air.Downloader) (Version: 2.0.7 - Vudu)

VUDU To Go (x32 Version: 2.0.7 - Vudu) Hidden

WebReg (x32 Version: 43.1.5.000 - Hewlett-Packard) Hidden

Win32DiskImager version 0.9.5 (HKLM-x32\\...\\{D074CE74-912A-4AD3-A0BF-3937D9D01F17}_is1) (Version: 0.9.5 - ImageWriter Developers)

Windows Live Essentials (HKLM-x32\\...\\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)

WinSCP 5.5.6 (HKLM-x32\\...\\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)

XBMC (HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\XBMC) (Version:  - Team XBMC)

YTD Video Downloader 4.9 (HKLM-x32\\...\\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.9 - GreenTree Applications SRL) <==== ATTENTION


==================== Custom CLSID (Whitelisted): ==========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== Restore Points =========================


08-08-2015 10:57:59 Windows Update

12-08-2015 19:13:55 Windows Update

15-08-2015 20:50:46 Windows Update

20-08-2015 18:13:11 Windows Update

22-08-2015 13:47:37 Windows Update

25-08-2015 17:13:05 Windows Update


==================== Hosts content: ==========================


(If needed Hosts: directive could be included in the fixlist to reset Hosts.)


2014-03-15 15:39 - 2014-03-15 15:39 - 00001794 ____N C:\\Windows\\system32\\Drivers\\etc\\hosts

127.0.0.1                activate.adobe.com

127.0.0.1                practivate.adobe.com

127.0.0.1                ereg.adobe.com

127.0.0.1                activate.wip3.adobe.com

127.0.0.1                wip3.adobe.com

127.0.0.1                3dns-3.adobe.com

127.0.0.1                3dns-2.adobe.com

127.0.0.1                adobe-dns.adobe.com

127.0.0.1                adobe-dns-2.adobe.com

127.0.0.1                adobe-dns-3.adobe.com

127.0.0.1                ereg.wip3.adobe.com

127.0.0.1                activate-sea.adobe.com

127.0.0.1                wwis-dubc1-vip60.adobe.com

127.0.0.1                activate-sjc0.adobe.com

127.0.0.1                               adobe.activate.com

127.0.0.1                               adobeereg.com                        

127.0.0.1                               www.adobeereg.com                    

127.0.0.1                               wwis-dubc1-vip60.adobe.com           

127.0.0.1                               125.252.224.90                       

127.0.0.1                               125.252.224.91

127.0.0.1                               hl2rcv.adobe.com



==================== Scheduled Tasks (Whitelisted) =============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


Task: {1B728705-C676-4AD9-B8F6-347E3E8A8D7E} - System32\\Tasks\\GoogleUpdateTaskMachineCore => C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe [2015-04-07] (Google Inc.)

Task: {32DB8D3B-1AE5-4371-ABCF-0BBCDA6EA7B3} - \\Runner IC -> No File <==== ATTENTION

Task: {46AFF864-863F-42C3-A9FD-3136A22FA9BC} - System32\\Tasks\\GoogleUpdateTaskMachineUA => C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe [2015-04-07] (Google Inc.)

Task: {4BF9C976-EB0D-4C76-A8A2-2CE6D2E530E3} - System32\\Tasks\\ProPCCleaner_Popup => C:\\Program Files (x86)\\Pro PC Cleaner\\Splash.exe <==== ATTENTION

Task: {4EDA2991-449F-4BDF-814F-EC59197DBD96} - System32\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000Core => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe [2014-07-26] (Facebook Inc.)

Task: {50077783-AC77-49CB-A27C-B466EEF4438B} - System32\\Tasks\\ProPCCleaner_Start => C:\\Program Files (x86)\\Pro PC Cleaner\\ProPCCleaner.exe <==== ATTENTION

Task: {51F5F522-909F-4F77-99BA-29DEEDD27CC0} - System32\\Tasks\\{BFFD1E77-20D5-466A-B270-9BBE48BEAAAF} => Firefox.exe http://www.skype.com/go/downloading?source=lightinstaller&amp;ver=5.8.0.154&amp;LastError=404\'>http://www.skype.com/go/downloading?source=lightinstaller&amp;ver=5.8.0.154&amp;LastError=404

Task: {5561C5CF-2764-4045-9124-251CDEA7BFEE} - System32\\Tasks\\DropboxSetup => C:\\Program Files (x86)\\Dropbox\\DropboxSetup\\DropboxSetup.exe [2015-06-23] ()

Task: {6844AC81-0FA4-4AC4-9560-4759C9753148} - System32\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000UA => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe [2014-07-26] (Facebook Inc.)

Task: {8332FB9F-36F0-4C8E-BBF7-8D415556C44F} - System32\\Tasks\\Apple\\AppleSoftwareUpdate => C:\\Program Files (x86)\\Apple Software Update\\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)

Task: {95F271AF-0D6E-4F4E-B956-4425B9156256} - System32\\Tasks\\AdobeAAMUpdater-1.0-Dell-PC-Dell => C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)

Task: {963A23E3-BE04-4F6F-BA30-D86BF2DAF81E} - System32\\Tasks\\{AEEBBC72-6C5F-4F67-A5E8-6F92BB76155F} => pcalua.exe -a C:\\dell\\drivers\\R311834\\Setup.exe -d C:\\dell\\drivers\\R311834

Task: {AB6A85E9-E43C-4DD4-9897-DA6A3EBD884B} - System32\\Tasks\\DropboxUpdateTaskMachineCore => C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [2015-07-06] (Dropbox, Inc.)

Task: {B264B876-A274-436A-A160-C4CC39D13345} - System32\\Tasks\\klcp_update => C:\\Program Files (x86)\\K-Lite Codec Pack\\Tools\\CodecTweakTool.exe [2015-06-01] ()

Task: {D873E55C-92EF-4DBE-803F-5A33C24A7B62} - System32\\Tasks\\Adobe Flash Player Updater => C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)

Task: {E3C97C3A-1F7C-4CC9-ABDD-E70FCCF22988} - System32\\Tasks\\DropboxUpdateTaskMachineUA => C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [2015-07-06] (Dropbox, Inc.)

Task: {F123F36F-B4D6-49D4-8D8C-68ADC143D928} - System32\\Tasks\\CCleanerSkipUAC => C:\\Program Files\\CCleaner\\CCleaner.exe [2015-06-02] (Piriform Ltd)

Task: {F889DA73-68BF-4DE8-9BCA-BEF0D89DF4A8} - \\Microsoft\\Windows\\Maintenance\\Update IC -> No File <==== ATTENTION


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


Task: C:\\Windows\\Tasks\\Adobe Flash Player Updater.job => C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe

Task: C:\\Windows\\Tasks\\DropboxUpdateTaskMachineCore.job => C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe

Task: C:\\Windows\\Tasks\\DropboxUpdateTaskMachineUA.job => C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe

Task: C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000Core.job => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe

Task: C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000UA.job => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe

Task: C:\\Windows\\Tasks\\GoogleUpdateTaskMachineCore.job => C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe

Task: C:\\Windows\\Tasks\\GoogleUpdateTaskMachineUA.job => C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe


==================== Loaded Modules (Whitelisted) ==============


2011-07-27 19:07 - 2011-07-27 19:07 - 01501696 _____ () C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\Libeay32.dll

2014-09-26 13:41 - 2014-09-26 13:41 - 01021088 _____ () C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll

2010-01-03 00:42 - 2010-01-03 00:42 - 00098304 _____ () C:\\Program Files (x86)\\FileZilla FTP Client\\fzshellext_64.dll

2014-03-13 19:09 - 2013-05-15 16:30 - 00034304 _____ () C:\\Windows\\System32\\sst6clm.dll

2015-03-20 18:12 - 2015-03-20 18:12 - 00085832 _____ () C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\zlib1.dll

2015-03-20 18:12 - 2015-03-20 18:12 - 01346344 _____ () C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\libxml2.dll

2011-07-27 19:07 - 2011-07-27 19:07 - 01501696 _____ () C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\LIBEAY32.dll

2012-10-29 21:16 - 2011-04-10 09:40 - 00094208 _____ () C:\\Windows\\System32\\IccLibDll_x64.dll

2012-03-09 08:58 - 2012-03-09 08:58 - 00462712 _____ () C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe

2012-03-09 08:58 - 2012-03-09 08:58 - 00057208 _____ () C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrvPS.dll

2012-11-30 07:59 - 2012-11-30 07:59 - 00093696 _____ () C:\\Program Files (x86)\\FileZilla FTP Client\\fzshellext.dll

2015-08-27 21:04 - 2015-08-27 21:04 - 00071168 _____ () c:\\users\\dell\\appdata\\local\\temp\\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsknlqv.dll

2015-07-06 17:37 - 2015-08-06 06:49 - 00012800 _____ () C:\\Program Files (x86)\\Dropbox\\Client\\QtQuick.2\\qtquick2plugin.dll

2015-07-06 17:37 - 2015-08-06 06:49 - 00779776 _____ () C:\\Program Files (x86)\\Dropbox\\Client\\QtQuick\\Controls\\qtquickcontrolsplugin.dll

2015-07-31 09:25 - 2015-08-06 06:49 - 00056320 _____ () C:\\Program Files (x86)\\Dropbox\\Client\\QtQuick\\Layouts\\qquicklayoutsplugin.dll

2015-07-06 17:37 - 2015-08-06 06:49 - 00012288 _____ () C:\\Program Files (x86)\\Dropbox\\Client\\QtQuick\\Window.2\\windowplugin.dll

2010-01-09 19:18 - 2010-01-09 19:18 - 04254560 _____ () C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE14\\Cultures\\OFFICE.ODF

2010-01-21 00:34 - 2010-01-21 00:34 - 08793952 _____ () C:\\Program Files (x86)\\Microsoft Office\\Office14\\1033\\GrooveIntlResource.dll

2015-08-12 20:29 - 2015-08-12 20:29 - 17482952 _____ () C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_18_0_0_232.dll


==================== Alternate Data Streams (Whitelisted) =========


(If an entry is included in the fixlist, only the ADS will be removed.)


AlternateDataStreams: C:\\ProgramData\\TEMP:054203E4

AlternateDataStreams: C:\\Users\\Dell\\Cookies:PmPGidEOaZqT89V0moNt

AlternateDataStreams: C:\\Users\\Dell\\AppData\\Local\\bkXKtCtOe8RNGC:wgbj4lKksCXPwJclKBPIvvYbVF

AlternateDataStreams: C:\\Users\\Dell\\AppData\\Local\\UAMzI1IORQ4aFT:5ZMvPo4E6kWwNe5kqGy1lMCjhd


==================== Safe Mode (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The \"AlternateShell\" will be restored.)



==================== EXE Association (Whitelisted) ===============


(If an entry is included in the fixlist, the registry item will be restored to default or removed.)



==================== Internet Explorer trusted/restricted ===============


(If an entry is included in the fixlist, it will be removed from the registry.)



==================== Other Areas ============================


(Currently there is no automatic fix for this section.)


HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\Control Panel\\Desktop\\\\Wallpaper -> C:\\Users\\Dell\\AppData\\Roaming\\Microsoft\\Windows\\Themes\\TranscodedWallpaper.jpg

DNS Servers: 82.163.143.137 - 82.163.142.139

HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.


==================== MSCONFIG/TASK MANAGER disabled items ==


(Currently there is no automatic fix for this section.)


MSCONFIG\\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\\Windows\\pss\\HP Digital Imaging Monitor.lnk.CommonStartup

MSCONFIG\\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk => C:\\Windows\\pss\\HP Image Zone Fast Start.lnk.CommonStartup

MSCONFIG\\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\\Windows\\pss\\McAfee Security Scan Plus.lnk.CommonStartup

MSCONFIG\\startupfolder: C:^Users^Dell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ Star Fox 64 (U) (V1.1) [!].lnk => C:\\Windows\\pss\\ Star Fox 64 (U) (V1.1) [!].lnk.Startup

MSCONFIG\\startupfolder: C:^Users^Dell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Starfox 64.lnk => C:\\Windows\\pss\\Starfox 64.lnk.Startup

MSCONFIG\\startupreg: Adobe ARM => \"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"

MSCONFIG\\startupreg: Adobe Creative Cloud => \"C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\ACC\\Creative Cloud.exe\" --showwindow=false --onOSstartup=true

MSCONFIG\\startupreg: AdobeCS5ServiceManager => \"C:\\Program Files (x86)\\Common Files\\Adobe\\CS5ServiceManager\\CS5ServiceManager.exe\" -launchedbylogin

MSCONFIG\\startupreg: APSDaemon => \"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"

MSCONFIG\\startupreg: iTunesHelper => \"C:\\Program Files\\iTunes\\iTunesHelper.exe\"

MSCONFIG\\startupreg: Skype => \"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun

MSCONFIG\\startupreg: SunJavaUpdateSched => \"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"

MSCONFIG\\startupreg: SwitchBoard => C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe

MSCONFIG\\startupreg: uTorrent => \"C:\\Users\\Dell\\AppData\\Roaming\\uTorrent\\uTorrent.exe\"  /MINIMIZED


==================== FirewallRules (Whitelisted) ===============


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


FirewallRules: [{90CB519D-14B1-49FB-B0FD-E6AB71F2309A}] => (Allow) C:\\Program Files\\Intel\\WiFi\\bin\\PanDhcpDns.exe

FirewallRules: [{7A46B50B-531D-402F-8EC9-02195ADD3347}] => (Allow) C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

FirewallRules: [{9662997C-9AE6-4BB2-9AAB-D71F843DBE29}] => (Allow) C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

FirewallRules: [{36243EC4-E047-48B4-8F71-E46F27D8E2DD}] => (Allow) C:\\Program Files (x86)\\Windows Live\\Contacts\\wlcomm.exe

FirewallRules: [{71F746B8-422C-4D4C-8274-0C029D0AD08D}] => (Allow) LPort=2869

FirewallRules: [{DF7BF61A-A7C1-470B-8D72-8E51FE9BFF05}] => (Allow) LPort=1900

FirewallRules: [{4E319ACD-DEA5-4947-9A3D-D7BBFE828D6D}] => (Allow) C:\\Program Files (x86)\\Windows Live\\Messenger\\msnmsgr.exe

FirewallRules: [TCP Query User{D48258FE-CD16-4358-8944-B23C645CB0FD}C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe] => (Allow) C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe

FirewallRules: [UDP Query User{A1876EBF-48D8-4BA7-AB0C-97F92E2C2696}C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe] => (Allow) C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe

FirewallRules: [TCP Query User{47ECE932-9E73-4DB9-AC20-2D37235EB0BD}C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe] => (Allow) C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe

FirewallRules: [UDP Query User{34FAD6F1-BC72-45E0-8E87-B7CAC3C9F6D7}C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe] => (Allow) C:\\program files (x86)\\renewed vision\\propresenter 5\\propresenter.exe

FirewallRules: [{12EFD3DF-9CDB-49C4-9CBC-3619A7FCEBDF}] => (Block) %ProgramFiles%\\Adobe\\Adobe Photoshop CS6 (64 Bit)\\Photoshop.exe

FirewallRules: [{F3C6F289-732C-4205-91CD-F46252C51AD6}] => (Allow) C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe

FirewallRules: [{79E4F3C3-29BA-435F-96D5-57E2F2585D4E}] => (Allow) C:\\Program Files\\Bonjour\\mDNSResponder.exe

FirewallRules: [{5F89CAE5-4A5F-4399-8F2E-D1CB2422C3DA}] => (Allow) C:\\Program Files\\Bonjour\\mDNSResponder.exe

FirewallRules: [{56AFEA7A-1575-408E-A050-8D8D7D58201A}] => (Allow) C:\\Program Files (x86)\\Bonjour\\mDNSResponder.exe

FirewallRules: [{3CF840D8-D0FE-455C-B9AD-864369BBEADF}] => (Allow) C:\\Program Files (x86)\\Bonjour\\mDNSResponder.exe

FirewallRules: [TCP Query User{24B9A623-457D-4C7A-AABD-19329F4F4DFB}C:\\users\\dell\\downloads\\utorrent.exe] => (Allow) C:\\users\\dell\\downloads\\utorrent.exe

FirewallRules: [UDP Query User{E3C7709D-2010-44D9-952F-79C0248DC777}C:\\users\\dell\\downloads\\utorrent.exe] => (Allow) C:\\users\\dell\\downloads\\utorrent.exe

FirewallRules: [TCP Query User{BD3CA439-4F10-4BB6-A489-429BCADFC4FF}C:\\program files\\airparrot\\airparrot.exe] => (Block) C:\\program files\\airparrot\\airparrot.exe

FirewallRules: [UDP Query User{5DD1CA3E-C08D-4269-AE34-2593BB488EE6}C:\\program files\\airparrot\\airparrot.exe] => (Block) C:\\program files\\airparrot\\airparrot.exe

FirewallRules: [TCP Query User{F7F6A428-DA89-4D82-B540-0CA7AF83D924}C:\\program files (x86)\\xbmc\\xbmc.exe] => (Allow) C:\\program files (x86)\\xbmc\\xbmc.exe

FirewallRules: [UDP Query User{DCEEABB7-4295-4327-8CD0-10D43DCE3479}C:\\program files (x86)\\xbmc\\xbmc.exe] => (Allow) C:\\program files (x86)\\xbmc\\xbmc.exe

FirewallRules: [TCP Query User{D866B982-3D1B-4284-AD5A-FFDFB19C2281}C:\\program files (x86)\\xbmc\\xbmc.exe] => (Allow) C:\\program files (x86)\\xbmc\\xbmc.exe

FirewallRules: [UDP Query User{DDC78A0E-6A35-4061-A932-3686C1AD4400}C:\\program files (x86)\\xbmc\\xbmc.exe] => (Allow) C:\\program files (x86)\\xbmc\\xbmc.exe

FirewallRules: [{7BE72BE4-EDAA-4333-B4FB-7D37D26E4040}] => (Allow) C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe

FirewallRules: [{BC23A9A0-1394-4705-95CB-FB69942789F7}] => (Allow) C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe

FirewallRules: [{87A77524-AEB5-4960-9D07-CA91EC8FAA0C}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\IDS.Application.exe

FirewallRules: [{AE5FBBDA-2DBC-4D5A-B186-1B1FB61C3114}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\IDS.Application.exe

FirewallRules: [{F0284745-2AD3-4AF8-A927-C4EA3529812E}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\OrderSupplies.exe

FirewallRules: [{C3B50453-891C-4D7F-8411-780B13B2DBAF}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\OrderSupplies.exe

FirewallRules: [{A153EB7E-746C-4153-9BC8-2EB72960D5A5}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\IDSAlert.exe

FirewallRules: [{1165661B-DCCA-46F5-9CA4-8371CB91DFE3}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\IDSAlert.exe

FirewallRules: [{4264EC8E-60E2-4205-AA9C-34EEA6DE3926}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\uninstall.exe

FirewallRules: [{EA68E3B6-47C2-4AEB-B2DD-9AB3677463B5}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\uninstall.exe

FirewallRules: [{1A19E8C7-6412-494E-8C58-C14633F2F841}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\CDAS2PC\\CDAS2PC.exe

FirewallRules: [{EF2E7A3D-8D27-4BEF-BDEC-9577C1C52258}] => (Allow) C:\\Program Files (x86)\\Samsung\\Easy Printer Manager\\CDAS2PC\\CDAS2PC.exe

FirewallRules: [{8305A787-CE5F-42CB-8E0F-397C40782F6D}] => (Allow) C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS5933\\hppiw.exe

FirewallRules: [{FA7D0EFB-0C8A-4A78-849E-2782609FC500}] => (Allow) C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS5933\\hppiw.exe

FirewallRules: [{9E22AD17-2812-4A30-8D27-3CA37D727F08}] => (Allow) C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS595E\\hppiw.exe

FirewallRules: [{12FBAF75-F3B3-4D35-A290-011E5B9FBFAC}] => (Allow) C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS595E\\hppiw.exe

FirewallRules: [{E0089A7E-4277-4E74-8D2D-7D5883176C12}] => (Allow) C:\\Users\\Dell\\AppData\\Local\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe

FirewallRules: [TCP Query User{A21F6627-7689-4281-BA73-000285BDC1A1}C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe] => (Block) C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe

FirewallRules: [UDP Query User{BBFEF821-1FF0-4A04-8725-097D20A97550}C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe] => (Block) C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe

FirewallRules: [TCP Query User{402E9E71-A46D-4290-B374-2218BA19BD0E}C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe] => (Block) C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe

FirewallRules: [UDP Query User{7C177AA5-3ADC-4885-8519-C120BEBC8632}C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe] => (Block) C:\\users\\dell\\appdata\\roaming\\mozilla\\firefox\\profiles\\fud95ddr.default\\extensions\\jid1-4p0kohsjxu1qgg@jetpack\\resources\\hola_firefox_ext\\data\\plugins\\hola_plugin_x64.exe

FirewallRules: [TCP Query User{77A26AC9-ADCD-44C3-9223-3412120AC75B}C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe] => (Allow) C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe

FirewallRules: [UDP Query User{77624F38-562C-46D5-9F8D-B17833C97F00}C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe] => (Allow) C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe

FirewallRules: [{3EA7B29D-006B-4B6D-ABBE-58EF162BA43C}] => (Allow) C:\\Users\\Dell\\AppData\\Roaming\\OAS\\oas.exe

FirewallRules: [{63BD8508-E130-47A3-8546-D06C8DCF9884}] => (Allow) C:\\Users\\Dell\\AppData\\Roaming\\OAS\\oasupd.exe

FirewallRules: [{4DB65F31-1BCF-4FFD-9A73-9D2239909A20}] => (Allow) C:\\Users\\Dell\\AppData\\Roaming\\uTorrent\\uTorrent.exe

FirewallRules: [{0B8EA605-9D9F-4596-951A-3246BECF4A09}] => (Allow) C:\\Users\\Dell\\AppData\\Roaming\\uTorrent\\uTorrent.exe

FirewallRules: [TCP Query User{C85CAEC6-9A80-4B25-9D26-543ACA8BFDD0}C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe] => (Block) C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe

FirewallRules: [UDP Query User{A77CB1FF-29BE-4AF5-B264-230CF4513606}C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe] => (Block) C:\\users\\dell\\appdata\\local\\hola\\firefox\\app\\hola_plugin.exe

FirewallRules: [{B146B132-AF68-48E7-A55C-47990C22F1E2}] => (Allow) C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe

FirewallRules: [{B3C9CEB6-C312-4403-A795-A64AE484A411}] => (Allow) C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe

FirewallRules: [TCP Query User{C4A88D20-45F4-4605-B064-9AEBE004436D}F:\\openlpportable\\app\\openlp\\openlp.exe] => (Allow) F:\\openlpportable\\app\\openlp\\openlp.exe

FirewallRules: [UDP Query User{948CEEDB-D79C-4454-A746-59DC45B23179}F:\\openlpportable\\app\\openlp\\openlp.exe] => (Allow) F:\\openlpportable\\app\\openlp\\openlp.exe

FirewallRules: [{D72FF84A-3692-4ACA-9DD4-F5D716572508}] => (Allow) C:\\Program Files\\iTunes\\iTunes.exe

FirewallRules: [{013B2226-BE8E-4E36-BADB-733C73D40790}] => (Allow) C:\\Program Files (x86)\\TeamViewer\\TeamViewer.exe

FirewallRules: [{7B3C9EEC-C19D-446F-A209-55D9A2C10A73}] => (Allow) C:\\Program Files (x86)\\TeamViewer\\TeamViewer.exe

FirewallRules: [{B3C9F9EC-786C-4F64-B89C-9FD64B439E61}] => (Allow) C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe

FirewallRules: [{8A26FBF5-E75E-4BE1-BB7B-6044663E8A2C}] => (Allow) C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe

FirewallRules: [{4A5D7CF4-A1D0-4509-809B-46854F09BEF1}] => (Allow) C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe

FirewallRules: [TCP Query User{25CF736C-2270-457B-8E59-3795DDF954B7}E:\\openlpportable\\app\\openlp\\openlp.exe] => (Allow) E:\\openlpportable\\app\\openlp\\openlp.exe

FirewallRules: [UDP Query User{75458893-04BD-465F-94FE-34F2C3910E97}E:\\openlpportable\\app\\openlp\\openlp.exe] => (Allow) E:\\openlpportable\\app\\openlp\\openlp.exe

FirewallRules: [{E73DFDAA-11DE-440A-B2DF-EEB4EEF82195}] => (Allow) C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe


==================== Faulty Device Manager Devices =============



==================== Event log errors: =========================


Application errors:

==================

Error: (08/27/2015 09:04:00 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/25/2015 05:33:22 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: Activation context generation failed for \"C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1\".Error in manifest or policy file \"C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2\" on line C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Component 2: C:\\Windows\\WinSxS\\manifests\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.


Error: (08/25/2015 05:02:41 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 06:29:48 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: Activation context generation failed for \"C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1\".Error in manifest or policy file \"C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2\" on line C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Component 2: C:\\Windows\\WinSxS\\manifests\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.


Error: (08/23/2015 06:10:50 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 05:35:28 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 07:08:33 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/22/2015 01:35:44 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/22/2015 10:20:11 AM) (Source: Application Hang) (EventID: 1002) (User: )

Description: The program sublime_text.exe version 1.0.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.


Process ID: 12c8


Start Time: 01d0dc6c4b6aeba8


Termination Time: 956


Application Path: C:\\Program Files\\Sublime Text 3\\sublime_text.exe


Report Id: 4d1aaf7f-4863-11e5-b23f-4ceb4210a3f5


Error: (08/22/2015 09:40:51 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003



System errors:

=============

Error: (08/27/2015 09:06:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/25/2015 05:04:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/23/2015 06:12:52 PM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/23/2015 05:37:34 PM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/23/2015 07:10:32 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/23/2015 07:08:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The HP Support Solutions Framework Service service failed to start due to the following error:

%%1053


Error: (08/23/2015 07:08:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: )

Description: A timeout was reached (30000 milliseconds) while waiting for the HP Support Solutions Framework Service service to connect.


Error: (08/22/2015 01:37:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126


Error: (08/22/2015 01:33:18 PM) (Source: Microsoft Antimalware) (EventID: 2004) (User: )

Description: %60 has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.


    Signatures Attempted: %24


    Error Code: 0x80070002


    Error description: The system cannot find the file specified.


    Signature version: 0.0.0.0;0.0.0.0


    Engine version: %600


Error: (08/22/2015 09:42:57 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The HP Network Devices Support service terminated with the following error:

%%126



Microsoft Office:

=========================

Error: (08/27/2015 09:04:00 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/25/2015 05:33:22 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\\Windows\\WinSxS\\manifests\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestc:\\program files (x86)\\Adobe\\adobe creative cloud\\Utils\\Creative Cloud Uninstaller.exe


Error: (08/25/2015 05:02:41 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 06:29:48 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: C:\\Windows\\WinSxS\\manifests\\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\\Windows\\WinSxS\\manifests\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestc:\\program files (x86)\\Adobe\\adobe creative cloud\\Utils\\Creative Cloud Uninstaller.exe


Error: (08/23/2015 06:10:50 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 05:35:28 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/23/2015 07:08:33 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/22/2015 01:35:44 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003


Error: (08/22/2015 10:20:11 AM) (Source: Application Hang) (EventID: 1002) (User: )

Description: sublime_text.exe1.0.0.112c801d0dc6c4b6aeba8956C:\\Program Files\\Sublime Text 3\\sublime_text.exe4d1aaf7f-4863-11e5-b23f-4ceb4210a3f5


Error: (08/22/2015 09:40:51 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA \"Win32_Processor\" AND TargetInstance.LoadPercentage > 990x80041003



==================== Memory info ===========================


Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz

Percentage of memory in use: 35%

Total physical RAM: 8098.05 MB

Available physical RAM: 5251.55 MB

Total Virtual: 16194.27 MB

Available Virtual: 13416.33 MB


==================== Drives ================================


Drive c: () (Fixed) (Total:931.41 GB) (Free:624.92 GB) NTFS


==================== MBR & Partition Table ==================


========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E600B0FB)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)


==================== End of Addition.txt ============================



8
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 27, 2015, 07:55:13 AM »

Here are my Farbar logs:


 


 


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:26-08-2015

Ran by Dell (administrator) on DELL-PC (27-08-2015 22:52:48)

Running from C:\\Users\\Dell\\Downloads

Loaded Profiles: Dell & UpdatusUser (Available Profiles: Dell & UpdatusUser)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: FF)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/\'>http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/


==================== Processes (Whitelisted) =================


(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)


(NVIDIA Corporation) C:\\Windows\\System32\\nvvsvc.exe

(Microsoft Corporation) C:\\Program Files\\Microsoft Security Client\\MsMpEng.exe

(Microsoft Corporation) C:\\Windows\\System32\\wlanext.exe

(NVIDIA Corporation) C:\\Program Files\\NVIDIA Corporation\\Display\\NvXDSync.exe

(NVIDIA Corporation) C:\\Windows\\System32\\nvvsvc.exe

(SUPERAntiSpyware.com) C:\\Program Files\\SUPERAntiSpyware\\SASCore64.exe

(Intel Corporation) C:\\Program Files\\Intel\\BluetoothHS\\BTHSAmpPalService.exe

(Apple Inc.) C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe

(Apple Inc.) C:\\Program Files\\Bonjour\\mDNSResponder.exe

(Intel(R) Corporation) C:\\Program Files\\Intel\\BluetoothHS\\BTHSSecurityMgr.exe

(Scarlet.Crush Productions) C:\\Program Files\\Scarlet.Crush Productions\\bin\\ScpService.exe

(Intel(R) Corporation) C:\\Program Files\\Intel\\WiFi\\bin\\EvtEng.exe

(Hewlett-Packard Company) C:\\Program Files (x86)\\Hp\\Common\\HPSupportSolutionsFrameworkService.exe

(Intel(R) Corporation) C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\iFrmewrk.exe

(Intel(R) Corporation) C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\RegSrvc.exe

(NVIDIA Corporation) C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

(Intel Corporation) C:\\Windows\\System32\\igfxtray.exe

(TeamViewer GmbH) C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe

(Microsoft Corp.) C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLIDSVC.EXE

(Intel Corporation) C:\\Windows\\System32\\hkcmd.exe

(Microsoft Corp.) C:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLIDSVCM.EXE

(Intel Corporation) C:\\Windows\\System32\\igfxpers.exe

(Microsoft Corporation) C:\\Program Files\\Microsoft Security Client\\msseces.exe

(Microsoft Corporation) C:\\Windows\\System32\\PrintIsolationHost.exe

() C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe

(Microsoft Corporation) C:\\Windows\\System32\\dllhost.exe

(Microsoft Corporation) C:\\Program Files\\Microsoft Xbox 360 Accessories\\XBoxStat.exe

(Samsung) C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe

(SUPERAntiSpyware) C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe

(Adobe Systems Incorporated) C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\AAM Updates Notifier.exe

(Samsung Electronics Co., Ltd.) C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe

(Hewlett-Packard Company) C:\\Program Files (x86)\\Hp\\HP Software Update\\hpwuSchd2.exe

(Dropbox, Inc.) C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe

(Piriform Ltd) C:\\Program Files\\CCleaner\\CCleaner64.exe

(Intel Corporation) C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

(NVIDIA Corporation) C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

(Intel Corporation) C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

(Mozilla Corporation) C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe

(Microsoft Corporation) C:\\Program Files\\Microsoft Security Client\\NisSrv.exe

(Trend Micro Inc.) C:\\Users\\Dell\\Downloads\\HijackThis.exe

(Microsoft Corporation) C:\\Windows\\SysWOW64\\notepad.exe

(Adobe Systems, Inc.) C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerPlugin_18_0_0_232.exe

(Adobe Systems, Inc.) C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerPlugin_18_0_0_232.exe



==================== Registry (Whitelisted) ===========================


(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)


HKLM\\...\\Run: [IntelPAN] => C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\iFrmewrk.exe [1935120 2011-07-27] (Intel(R) Corporation)

HKLM\\...\\Run: [NVHotkey] => rundll32.exe C:\\Windows\\system32\\nvHotkey.dll,Start

HKLM\\...\\Run: [MSC] => c:\\Program Files\\Microsoft Security Client\\msseces.exe [1266912 2013-10-23] (Microsoft Corporation)

HKLM\\...\\Run: [CDAServer] => C:\\Program Files\\Common Files\\Common Desktop Agent\\CDASrv.exe [462712 2012-03-09] ()

HKLM\\...\\Run: [AdobeAAMUpdater-1.0] => C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe [557768 2014-10-14] (Adobe Systems Incorporated)

HKLM\\...\\Run: [XboxStat] => C:\\Program Files\\Microsoft Xbox 360 Accessories\\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)

HKLM-x32\\...\\Run: [BCSSync] => C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)

HKLM-x32\\...\\Run: [Dell Webcam Central] => C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell2.exe [409744 2009-06-24] (Creative Technology Ltd)

HKLM-x32\\...\\Run: [KiesTrayAgent] => C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)

HKLM-x32\\...\\Run: [HP Software Update] => C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)

HKLM-x32\\...\\Run: [HP Component Manager] => C:\\Program Files (x86)\\HP\\hpcoretech\\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)

HKLM-x32\\...\\Run: [QuickTime Task] => C:\\Program Files (x86)\\QuickTime\\QTTask.exe [421888 2014-10-02] (Apple Inc.)

HKLM-x32\\...\\Run: [Dropbox] => C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe [39179912 2015-08-06] (Dropbox, Inc.)

Winlogon\\Notify\\igfxcui: C:\\Windows\\system32\\igfxdev.dll (Intel Corporation)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [AdobeBridge] => [X]

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [Cloud Sync Application] => C:\\Program Files (x86)\\Renewed Vision\\ProPresenter 5\\CloudSyncApp.exe [169984 2014-01-27] (Renewed Vision, Inc)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [Facebook Update] => C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe [138096 2014-07-26] (Facebook Inc.)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [KiesPreload] => C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe [1562264 2014-07-25] (Samsung)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [KiesAirMessage] => C:\\Program Files (x86)\\Samsung\\Kies\\KiesAirMessage.exe -startup

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [CCleaner Monitoring] => C:\\Program Files\\CCleaner\\CCleaner64.exe [8358680 2015-06-02] (Piriform Ltd)

HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Run: [SUPERAntiSpyware] => C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe [7930136 2015-07-31] (SUPERAntiSpyware)

AppInit_DLLs-x32: c:\\windows\\syswow64\\nvinit.dll => c:\\windows\\syswow64\\nvinit.dll [193128 2011-04-22] (NVIDIA Corporation)

ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\CoreSyncExtension\\CoreSync_x64.dll [2014-09-26] ()

ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt64.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\\Program Files (x86)\\Dropbox\\Client\\DropboxExt.27.dll [2015-08-06] (Dropbox, Inc.)

CHR HKLM\\SOFTWARE\\Policies\\Google: Policy restriction <======= ATTENTION


==================== Internet (Whitelisted) ====================


(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)










HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =

SearchScopes: HKU\\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKU\\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =



Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

Tcpip\\Parameters: [DhcpNameServer] 192.168.0.1

Tcpip\\..\\Interfaces\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}: [NameServer] 82.163.143.137,82.163.142.139

Tcpip\\..\\Interfaces\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}: [DhcpNameServer] 192.168.0.1

Tcpip\\..\\Interfaces\\{BF7548A4-4B37-4112-B6B7-87AD8793FEF1}: [DhcpNameServer] 172.20.10.1


FireFox:

========

FF ProfilePath: C:\\Users\\Dell\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\9zk16fkx.default-1438300192999

FF Plugin: @adobe.com/FlashPlayer -> C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_18_0_0_232.dll [2015-08-12] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files\\Microsoft Silverlight\\5.1.30214.0\\npctrl.dll [2014-02-13] ( Microsoft Corporation)

FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\\PROGRA~1\\MICROS~3\\Office14\\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\Utils\\npAdobeAAMDetect64.dll [2014-10-15] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_18_0_0_232.dll [2015-08-12] ()

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\\Program Files (x86)\\iTunes\\Mozilla Plugins\\npitunes.dll [2014-10-30] ()

FF Plugin-x32: @ei.InboxAce_1g.com/Plugin -> C:\\Program Files (x86)\\InboxAce_1gEI\\Installr\\1.bin\\NP1gEISB.dll [No File]

FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll [2014-07-11] (Oracle Corporation)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\\Program Files (x86)\\Microsoft Silverlight\\5.1.30214.0\\npctrl.dll [2014-02-13] ( Microsoft Corporation)

FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\\PROGRA~2\\MICROS~3\\Office14\\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\\PROGRA~2\\MICROS~3\\Office14\\NPSPWRAP.DLL [2010-01-09] (Microsoft Corporation)

FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll [2012-09-12] (Microsoft Corporation)

FF Plugin-x32: @nvidia.com/3DVision -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dv.dll [2011-04-21] (NVIDIA Corporation)

FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\npnv3dvstreaming.dll [2011-04-21] (NVIDIA Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.1\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\\Program Files (x86)\\Google\\Update\\1.3.28.1\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\\Program Files (x86)\\VideoLAN\\VLC\\npvlc.dll [2015-04-13] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\\Program Files (x86)\\Adobe\\Reader 11.0\\Reader\\AIR\\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\\Program Files (x86)\\Adobe\\Adobe Creative Cloud\\Utils\\npAdobeAAMDetect32.dll [2014-10-15] (Adobe Systems)

FF Plugin HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000: @hola.org/vlc,version=1.8.204 -> C:\\Users\\Dell\\AppData\\Local\\Hola\\firefox\\app\\vlc No File

FF Plugin HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\\Users\\Dell\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)

FF HKU\\S-1-5-21-2799920661-1438349000-4008728122-1000\\...\\Firefox\\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\\ProgramData\\McAfee Security Scan\\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi

FF Extension: McAfee Security Scan Plus - C:\\ProgramData\\McAfee Security Scan\\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]


Chrome:

=======

CHR dev: Chrome dev build detected! <======= ATTENTION

CHR Profile: C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default

CHR Extension: (Chrome Hotword Shared Module) - C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lccekmodgklaepjeofjdjpbminllajkg [2015-07-11]

CHR Extension: (Chrome Web Store Payments) - C:\\Users\\Dell\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-11]


==================== Services (Whitelisted) ========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R2 !SASCORE; C:\\Program Files\\SUPERAntiSpyware\\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)

R2 Apple Mobile Device Service; C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)

S2 dbupdate; C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [134512 2015-07-06] (Dropbox, Inc.)

S3 dbupdatem; C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe [134512 2015-07-06] (Dropbox, Inc.)

R2 Ds3Service; C:\\Program Files\\Scarlet.Crush Productions\\bin\\ScpService.exe [388352 2013-05-05] (Scarlet.Crush Productions)

R2 HPSupportSolutionsFrameworkService; C:\\Program Files (x86)\\Hp\\Common\\HPSupportSolutionsFrameworkService.exe [89352 2014-09-15] (Hewlett-Packard Company)

S3 McComponentHostService; C:\\Program Files\\McAfee Security Scan\\3.8.150\\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)

R2 MsMpSvc; c:\\Program Files\\Microsoft Security Client\\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation)

S3 MyWiFiDHCPDNS; C:\\Program Files\\Intel\\WiFi\\bin\\PanDhcpDns.exe [340240 2011-07-27] ()

R3 NisSrv; c:\\Program Files\\Microsoft Security Client\\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation)

S3 SwitchBoard; C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]

R2 TeamViewer; C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe [5495056 2015-06-18] (TeamViewer GmbH)

S3 WinDefend; C:\\Program Files\\Windows Defender\\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

S3 aspnet_state; %SystemRoot%\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe [X]

S2 HPSLPSVC; C:\\Users\\Dell\\AppData\\Local\\Temp\\7zS595E\\hpslpsvc64.dll [X]


===================== Drivers (Whitelisted) ==========================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


R0 MpFilter; C:\\Windows\\System32\\DRIVERS\\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation)

R2 NisDrv; C:\\Windows\\System32\\DRIVERS\\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation)

R1 SASDIFSV; C:\\Program Files\\SUPERAntiSpyware\\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

R1 SASKUTIL; C:\\Program Files\\SUPERAntiSpyware\\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)

R3 ScpVBus; C:\\Windows\\System32\\DRIVERS\\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)

S3 MBAMSwissArmy; \\??\\C:\\Windows\\system32\\drivers\\MBAMSwissArmy.sys [X]


==================== NetSvcs (Whitelisted) ===================


(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



==================== One Month Created files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2015-08-27 22:52 - 2015-08-27 22:53 - 00020029 _____ C:\\Users\\Dell\\Downloads\\FRST.txt

2015-08-27 22:52 - 2015-08-27 22:52 - 02186752 _____ (Farbar) C:\\Users\\Dell\\Downloads\\FRST64.exe

2015-08-27 22:52 - 2015-08-27 22:52 - 00000000 ____D C:\\FRST

2015-08-27 22:43 - 2015-08-27 22:43 - 00011145 _____ C:\\Users\\Dell\\Downloads\\hijackthis.log

2015-08-27 22:42 - 2015-08-27 22:42 - 00388608 _____ (Trend Micro Inc.) C:\\Users\\Dell\\Downloads\\HijackThis.exe

2015-08-23 23:30 - 2015-08-23 23:30 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Skype

2015-08-23 07:22 - 2015-08-23 07:22 - 00112093 _____ C:\\Users\\Dell\\Downloads\\Esther.pptx

2015-08-22 14:22 - 2015-08-22 14:22 - 00001870 _____ C:\\Users\\Dell\\Downloads\\Come Praise & Glorify (Bob Kauflin, Tim Chester).xml

2015-08-22 14:22 - 2015-08-22 14:22 - 00001792 _____ C:\\Users\\Dell\\Downloads\\Here is Love (Matt Redman, William Rees, Robert Lowry).xml

2015-08-22 14:16 - 2015-08-22 14:16 - 00001813 _____ C:\\Users\\Dell\\Downloads\\It Is Well With My Soul (Philipp Bliss, Horatio G Spafford).xml

2015-08-20 23:58 - 2015-08-23 07:31 - 00000000 ____D C:\\Program Files\\Sublime Text 3

2015-08-20 23:58 - 2015-08-20 23:58 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\Sublime Text 3

2015-08-20 23:58 - 2015-08-20 23:58 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Sublime Text 3

2015-08-20 18:18 - 2015-08-20 22:00 - 00000000 ____D C:\\Users\\Dell\\Downloads\\dmps

2015-08-15 21:09 - 2015-08-15 21:09 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Dropbox

2015-07-31 10:13 - 2015-07-31 10:13 - 00000000 ____D C:\\SUPERDelete

2015-07-31 10:12 - 2015-08-23 07:31 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\SUPERAntiSpyware

2015-07-31 10:12 - 2015-08-23 07:31 - 00000000 ____D C:\\Program Files\\SUPERAntiSpyware

2015-07-31 10:12 - 2015-07-31 10:12 - 00001808 _____ C:\\Users\\Public\\Desktop\\SUPERAntiSpyware Professional.lnk

2015-07-31 10:12 - 2015-07-31 10:12 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\SUPERAntiSpyware.com

2015-07-31 10:12 - 2015-07-31 10:12 - 00000000 ____D C:\\ProgramData\\SUPERAntiSpyware.com

2015-07-31 10:09 - 2015-07-31 10:12 - 22854032 _____ (SUPERAntiSpyware) C:\\Users\\Dell\\Downloads\\SUPERAntiSpywarePro.exe


==================== One Month Modified files and folders ========


(If an entry is included in the fixlist, the file/folder will be moved.)


2015-08-27 22:52 - 2014-03-13 19:22 - 00000072 _____ C:\\Users\\Public\\LMDebug.log

2015-08-27 22:48 - 2015-07-06 17:36 - 00000904 _____ C:\\Windows\\Tasks\\DropboxUpdateTaskMachineUA.job

2015-08-27 22:29 - 2014-07-26 22:24 - 00000924 _____ C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000UA.job

2015-08-27 22:29 - 2014-07-26 22:24 - 00000902 _____ C:\\Windows\\Tasks\\FacebookUpdateTaskUserS-1-5-21-2799920661-1438349000-4008728122-1000Core.job

2015-08-27 22:29 - 2012-11-04 12:18 - 00000830 _____ C:\\Windows\\Tasks\\Adobe Flash Player Updater.job

2015-08-27 22:21 - 2012-12-02 20:27 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\Skype

2015-08-27 22:01 - 2015-04-07 16:42 - 00000898 _____ C:\\Windows\\Tasks\\GoogleUpdateTaskMachineUA.job

2015-08-27 21:48 - 2015-07-06 17:36 - 00000900 _____ C:\\Windows\\Tasks\\DropboxUpdateTaskMachineCore.job

2015-08-27 21:15 - 2012-10-29 20:51 - 02070609 _____ C:\\Windows\\WindowsUpdate.log

2015-08-27 21:11 - 2009-07-14 14:45 - 00021472 ____H C:\\Windows\\system32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2015-08-27 21:11 - 2009-07-14 14:45 - 00021472 ____H C:\\Windows\\system32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2015-08-27 21:05 - 2015-07-06 17:38 - 00000000 ___RD C:\\Users\\Dell\\Dropbox

2015-08-27 21:05 - 2015-07-06 17:36 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Dropbox

2015-08-27 21:04 - 2014-08-26 18:11 - 00000000 ____D C:\\Users\\Dell\\AppData\\Local\\Adobe

2015-08-27 21:03 - 2015-04-07 16:42 - 00000894 _____ C:\\Windows\\Tasks\\GoogleUpdateTaskMachineCore.job

2015-08-27 21:03 - 2012-10-29 21:23 - 00000000 ____D C:\\ProgramData\\NVIDIA

2015-08-27 21:03 - 2009-07-14 15:08 - 00000006 ____H C:\\Windows\\Tasks\\SA.DAT

2015-08-27 21:02 - 2015-06-28 11:25 - 00004190 _____ C:\\Windows\\setupact.log

2015-08-24 00:04 - 2015-04-07 16:43 - 00002183 _____ C:\\Users\\Public\\Desktop\\Google Chrome.lnk

2015-08-23 23:30 - 2014-11-30 18:07 - 00000000 ___RD C:\\Program Files (x86)\\Skype

2015-08-23 23:30 - 2014-05-26 17:08 - 00002697 _____ C:\\Users\\Public\\Desktop\\Skype.lnk

2015-08-23 23:30 - 2012-12-02 20:26 - 00000000 ____D C:\\ProgramData\\Skype

2015-08-23 17:45 - 2015-05-01 12:25 - 00000000 ____D C:\\Users\\Dell\\Desktop\\M&M Website

2015-08-23 07:31 - 2015-07-11 10:29 - 00000000 ____D C:\\Program Files (x86)\\Mozilla Firefox

2015-08-23 07:31 - 2015-04-07 16:43 - 00000000 ____D C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Google Chrome

2015-08-23 07:31 - 2012-11-24 18:20 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\uTorrent

2015-08-23 07:31 - 2012-10-31 17:16 - 00000000 ____D C:\\Program Files (x86)\\Mozilla Maintenance Service

2015-08-23 07:31 - 2009-07-14 13:20 - 00000000 ____D C:\\Windows\\registration

2015-08-23 07:31 - 2009-07-14 13:20 - 00000000 ____D C:\\Windows\\AppCompat

2015-08-22 13:55 - 2009-07-14 15:13 - 00796054 _____ C:\\Windows\\system32\\PerfStringBackup.INI

2015-08-22 13:37 - 2015-06-13 18:21 - 00000000 ____D C:\\Users\\Dell\\AppData\\Roaming\\vlc

2015-08-22 13:33 - 2012-10-29 20:51 - 00000000 ____D C:\\Users\\Dell

2015-08-16 16:39 - 2015-07-12 14:23 - 00004104 _____ C:\\Windows\\PFRO.log

2015-08-15 21:09 - 2015-07-06 17:24 - 00000000 ____D C:\\Program Files (x86)\\Dropbox

2015-08-12 20:29 - 2012-11-04 12:18 - 00778440 _____ (Adobe Systems Incorporated) C:\\Windows\\SysWOW64\\FlashPlayerApp.exe

2015-08-12 20:29 - 2012-11-04 12:18 - 00142536 _____ (Adobe Systems Incorporated) C:\\Windows\\SysWOW64\\FlashPlayerCPLApp.cpl

2015-08-12 20:29 - 2012-11-04 12:18 - 00003768 _____ C:\\Windows\\System32\\Tasks\\Adobe Flash Player Updater

2015-08-12 19:34 - 2015-07-14 19:35 - 00000000 ____D C:\\ProgramData\\YTD Video Downloader

2015-08-08 11:40 - 2012-10-29 20:59 - 00000000 ____D C:\\Users\\Dell\\Desktop\\N5110

2015-07-31 10:06 - 2015-06-28 10:37 - 00000000 ____D C:\\Program Files\\CCleaner

2015-07-31 09:49 - 2015-06-11 17:16 - 00000000 ____D C:\\Users\\Dell\\Desktop\\Old Firefox Data


==================== Files in the root of some directories =======


2014-12-06 08:09 - 2014-12-07 19:57 - 1019904 _____ () C:\\Users\\Dell\\AppData\\Roaming\\123 Cheese Prefsv3

2013-01-06 08:57 - 2013-01-06 08:57 - 0000132 _____ () C:\\Users\\Dell\\AppData\\Roaming\\Adobe PNG Format CS5 Prefs

2013-06-30 12:13 - 2008-07-07 13:22 - 0000014 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options.ini

2013-06-30 12:13 - 2012-07-07 13:04 - 0000003 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options_pdfcombine.ini

2013-06-30 12:13 - 2013-02-23 12:15 - 0000003 _____ () C:\\Users\\Dell\\AppData\\Roaming\\options_pdfrotator.ini

2013-06-30 12:13 - 2013-06-30 12:14 - 0000703 _____ () C:\\Users\\Dell\\AppData\\Roaming\\pdfsound.dll

2013-06-30 12:13 - 2013-06-09 09:38 - 0000053 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setting.ini

2013-06-30 12:13 - 2013-06-08 13:43 - 0000030 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup.ini

2013-06-30 12:13 - 2013-06-09 09:30 - 0000043 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup_pdfcombine.ini

2013-06-30 12:13 - 2013-06-09 10:34 - 0000043 _____ () C:\\Users\\Dell\\AppData\\Roaming\\setup_pdfrotator.ini

2015-04-03 17:12 - 2015-04-04 03:42 - 0000062 _____ () C:\\Users\\Dell\\AppData\\Roaming\\WB.CFG

2015-02-05 18:59 - 2015-02-05 19:04 - 0000600 _____ () C:\\Users\\Dell\\AppData\\Roaming\\winscp.rnd

2014-12-06 08:25 - 2015-06-14 18:55 - 0109925 _____ () C:\\Users\\Dell\\AppData\\Local\\ars.cache

2014-12-06 08:25 - 2015-06-14 18:55 - 0468633 _____ () C:\\Users\\Dell\\AppData\\Local\\census.cache

2014-10-11 19:24 - 2014-10-11 19:24 - 0000092 _____ () C:\\Users\\Dell\\AppData\\Local\\fusioncache.dat

2014-12-06 07:58 - 2014-12-06 07:58 - 0000036 _____ () C:\\Users\\Dell\\AppData\\Local\\housecall.guid.cache

2013-02-19 19:01 - 2015-02-05 18:46 - 0000600 _____ () C:\\Users\\Dell\\AppData\\Local\\PUTTY.RND

2015-04-06 14:56 - 2015-04-06 14:57 - 0011722 _____ () C:\\Users\\Dell\\AppData\\Local\\Temp-log.txt

2014-10-10 17:56 - 2014-10-10 18:14 - 0000372 _____ () C:\\ProgramData\\hpzinstall.log


Some files in TEMP:

====================

C:\\Users\\Dell\\AppData\\Local\\Temp\\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsknlqv.dll

C:\\Users\\Dell\\AppData\\Local\\Temp\\SkypeSetup.exe



==================== Bamital & volsnap =================


(There is no automatic fix for files that do not pass verification.)


C:\\Windows\\system32\\winlogon.exe => File is digitally signed

C:\\Windows\\system32\\wininit.exe => File is digitally signed

C:\\Windows\\SysWOW64\\wininit.exe => File is digitally signed

C:\\Windows\\explorer.exe => File is digitally signed

C:\\Windows\\SysWOW64\\explorer.exe => File is digitally signed

C:\\Windows\\system32\\svchost.exe => File is digitally signed

C:\\Windows\\SysWOW64\\svchost.exe => File is digitally signed

C:\\Windows\\system32\\services.exe => File is digitally signed

C:\\Windows\\system32\\User32.dll => File is digitally signed

C:\\Windows\\SysWOW64\\User32.dll => File is digitally signed

C:\\Windows\\system32\\userinit.exe => File is digitally signed

C:\\Windows\\SysWOW64\\userinit.exe => File is digitally signed

C:\\Windows\\system32\\rpcss.dll => File is digitally signed

C:\\Windows\\system32\\dnsapi.dll => File is digitally signed

C:\\Windows\\SysWOW64\\dnsapi.dll => File is digitally signed

C:\\Windows\\system32\\Drivers\\volsnap.sys => File is digitally signed



LastRegBack: 2015-08-23 18:27


==================== End of FRST.txt ============================



9
Tech Clinic / Can not get rit off Adds by Cloudscout
« on: August 27, 2015, 07:46:56 AM »

Hi guys,


 


I have followed many many online step by step guides on how to get rit off \"adds by cloudscout\" with no success... its a nasty piece of spyware thats almost diabling my entire system.. There are many things i am now unable to do besides getting pop up after pop up and silly adds left, right and centre. I hope someone here can help me .


 


Here is my HijackThis logg. Many thanks in advance


 


Logfile of Trend Micro HijackThis v2.0.5

Scan saved at 10:43:15 PM, on 27/08/2015

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v11.0 (11.00.9600.16521)


FIREFOX: 39.0 (x86 en-US)

Boot mode: Normal


Running processes:

C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe

C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\AAM Updates Notifier.exe

C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe

C:\\Program Files (x86)\\Hp\\HP Software Update\\hpwuSchd2.exe

C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe

C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe

C:\\Program Files (x86)\\Mozilla Firefox\\plugin-container.exe

C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerPlugin_18_0_0_232.exe

C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerPlugin_18_0_0_232.exe

C:\\Users\\Dell\\Downloads\\HijackThis.exe


R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Bar = Preserve

R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =

R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm

R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe,

O4 - HKLM\\..\\Run: [BCSSync] \"C:\\Program Files (x86)\\Microsoft Office\\Office14\\BCSSync.exe\" /DelayServices

O4 - HKLM\\..\\Run: [Dell Webcam Central] \"C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell2.exe\" /mode2

O4 - HKLM\\..\\Run: [KiesTrayAgent] C:\\Program Files (x86)\\Samsung\\Kies\\KiesTrayAgent.exe

O4 - HKLM\\..\\Run: [HP Software Update] \"C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe\"

O4 - HKLM\\..\\Run: [HP Component Manager] \"C:\\Program Files (x86)\\HP\\hpcoretech\\hpcmpmgr.exe\"

O4 - HKLM\\..\\Run: [QuickTime Task] \"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime

O4 - HKLM\\..\\Run: [Dropbox] \"C:\\Program Files (x86)\\Dropbox\\Client\\Dropbox.exe\" /systemstartup

O4 - HKCU\\..\\Run: [Cloud Sync Application] C:\\Program Files (x86)\\Renewed Vision\\ProPresenter 5\\CloudSyncApp.exe

O4 - HKCU\\..\\Run: [Facebook Update] \"C:\\Users\\Dell\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe\" /c /nocrashserver

O4 - HKCU\\..\\Run: [KiesPreload] C:\\Program Files (x86)\\Samsung\\Kies\\Kies.exe /preload

O4 - HKCU\\..\\Run: [KiesAirMessage] C:\\Program Files (x86)\\Samsung\\Kies\\KiesAirMessage.exe -startup

O4 - HKCU\\..\\Run: [CCleaner Monitoring] \"C:\\Program Files\\CCleaner\\CCleaner64.exe\" /MONITOR

O4 - HKCU\\..\\Run: [SUPERAntiSpyware] C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIE.dll

O9 - Extra \'Tools\' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIE.dll

O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIELinkedNotes.dll

O9 - Extra \'Tools\' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\\Program Files (x86)\\Microsoft Office\\Office14\\ONBttnIELinkedNotes.dll

O10 - Unknown file in Winsock LSP: c:\\program files (x86)\\common files\\microsoft shared\\windows live\\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\\program files (x86)\\common files\\microsoft shared\\windows live\\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab\'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\..\\{AB5AB876-2FBC-4E49-B2E5-F555096C785B}: NameServer = 82.163.143.137,82.163.142.139

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\OFFICE14\\MSOXMLMF.DLL

O20 - AppInit_DLLs: c:\\windows\\syswow64\\nvinit.dll

O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\\Program Files\\SUPERAntiSpyware\\SASCORE64.EXE

O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe

O23 - Service: @%SystemRoot%\\system32\\Alg.exe,-112 (ALG) - Unknown owner - C:\\Windows\\System32\\alg.exe (file missing)

O23 - Service: Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service (AMPPALR3) - Intel Corporation - C:\\Program Files\\Intel\\BluetoothHS\\BTHSAmpPalService.exe

O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe

O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe (file missing)

O23 - Service: Bonjour Service - Apple Inc. - C:\\Program Files\\Bonjour\\mDNSResponder.exe

O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\\Program Files\\Intel\\BluetoothHS\\BTHSSecurityMgr.exe

O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe

O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\\Program Files (x86)\\Dropbox\\Update\\DropboxUpdate.exe

O23 - Service: SCP DS3 Service (Ds3Service) - Scarlet.Crush Productions - C:\\Program Files\\Scarlet.Crush Productions\\bin\\ScpService.exe

O23 - Service: @%SystemRoot%\\system32\\efssvc.dll,-100 (EFS) - Unknown owner - C:\\Windows\\System32\\lsass.exe (file missing)

O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\\Program Files\\Intel\\WiFi\\bin\\EvtEng.exe

O23 - Service: @%systemroot%\\system32\\fxsresm.dll,-118 (Fax) - Unknown owner - C:\\Windows\\system32\\fxssvc.exe (file missing)

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe

O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe

O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\\Program Files (x86)\\Hp\\Common\\HPSupportSolutionsFrameworkService.exe

O23 - Service: @%SystemRoot%\\system32\\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\\Windows\\system32\\IEEtwCollector.exe (file missing)

O23 - Service: iPod Service - Apple Inc. - C:\\Program Files\\iPod\\bin\\iPodService.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\LMS\\LMS.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\\Program Files\\McAfee Security Scan\\3.8.150\\McCHSvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\\Windows\\System32\\msdtc.exe (file missing)

O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\\Program Files\\Intel\\WiFi\\bin\\PanDhcpDns.exe

O23 - Service: @%SystemRoot%\\System32\\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\\Windows\\system32\\nvvsvc.exe (file missing)

O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\\Program Files (x86)\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe

O23 - Service: @%systemroot%\\system32\\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\\Program Files\\Common Files\\Intel\\WirelessCommon\\RegSrvc.exe

O23 - Service: @%systemroot%\\system32\\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\\Windows\\system32\\locator.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\samsrv.dll,-1 (SamSs) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe

O23 - Service: @%SystemRoot%\\system32\\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\\Windows\\System32\\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\\system32\\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\\Windows\\System32\\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\\Windows\\system32\\sppsvc.exe (file missing)

O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\\Program Files (x86)\\NVIDIA Corporation\\3D Vision\\nvSCPAPISvr.exe

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe

O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\\Program Files (x86)\\TeamViewer\\TeamViewer_Service.exe

O23 - Service: @%SystemRoot%\\system32\\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\\Windows\\system32\\UI0Detect.exe (file missing)

O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\\Program Files (x86)\\Intel\\Intel(R) Management Engine Components\\UNS\\UNS.exe

O23 - Service: @%SystemRoot%\\system32\\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\vds.exe,-100 (vds) - Unknown owner - C:\\Windows\\System32\\vds.exe (file missing)

O23 - Service: @%systemroot%\\system32\\vssvc.exe,-102 (VSS) - Unknown owner - C:\\Windows\\system32\\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\\system32\\Wat\\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\\Windows\\system32\\Wat\\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\\system32\\wbengine.exe,-104 (wbengine) - Unknown owner - C:\\Windows\\system32\\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\\Windows\\system32\\wbem\\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\\Windows Media Player\\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\\Program Files (x86)\\Windows Media Player\\wmpnetwk.exe (file missing)


--

End of file - 11143 bytes

 


 


 


 



10
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 09, 2012, 04:02:55 AM »
Hi guestolo

I have defraged both partitions, here is the latest OTL logg:


OTL logfile created on: 9/02/2012 7:28:32 PM - Run 6
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 578.46 Mb Available Physical Memory | 56.53% Memory free
2.40 Gb Paging File | 1.91 Gb Available in Paging File | 79.40% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 5.54 Gb Free Space | 16.19% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 4.23 Gb Free Space | 10.51% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
PRC - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/07/26 00:26:20 | 000,528,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/04 09:29:15 | 000,165,784 | ---- | M] (DT Soft Ltd.) -- D:\DAEMON Tools\daemon.exe
PRC - [2006/06/13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE
PRC - [2005/02/23 12:05:52 | 002,301,952 | ---- | M] (Headlight Software, Inc.) -- C:\Program Files\GetRight\getright.exe
PRC - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/10/30 17:59:54 | 000,385,024 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2004/10/19 13:01:52 | 000,712,704 | ---- | M] (Microsoft) -- C:\Program Files\Microsoft Time Zone\TimeZone.exe
PRC - [2004/09/13 14:33:20 | 000,155,648 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004/09/07 19:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004/09/07 19:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
PRC - [2004/08/19 12:40:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/02/09 06:30:13 | 001,691,136 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020801\algo.dll
MOD - [2012/01/22 15:44:10 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b8c4ae52\mscorlib.dll
MOD - [2012/01/22 15:44:05 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cded7d4c\system.drawing.dll
MOD - [2012/01/22 15:43:41 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_f66f41a6\system.xml.dll
MOD - [2012/01/22 15:43:16 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_0ae88b83\system.windows.forms.dll
MOD - [2012/01/22 15:40:19 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0a4d6360\system.dll
MOD - [2012/01/18 01:32:25 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/18 01:32:23 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2011/11/04 02:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\SYSTEM32\quartz.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 00:27:01 | 001,640,216 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Resources.dll
MOD - [2011/07/26 00:26:57 | 000,256,424 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/11/28 17:09:04 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2009/11/28 17:09:04 | 000,006,656 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2009/11/28 17:09:01 | 000,614,400 | ---- | M] () -- c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
MOD - [2009/11/28 17:07:34 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2009/11/28 17:06:42 | 000,249,856 | ---- | M] () -- c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2009/11/28 17:06:42 | 000,045,056 | ---- | M] () -- c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2009/11/28 17:06:41 | 000,368,640 | ---- | M] () -- c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2009/11/28 17:06:41 | 000,163,840 | ---- | M] () -- c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2009/11/28 17:06:41 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2009/11/28 17:06:41 | 000,007,168 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2009/11/28 17:06:40 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
MOD - [2009/11/28 17:06:40 | 000,028,672 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2009/11/28 17:06:40 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2009/11/28 17:02:58 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
MOD - [2009/11/28 17:02:57 | 000,192,512 | ---- | M] () -- c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
MOD - [2009/11/28 17:02:57 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2009/11/28 17:02:57 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
MOD - [2009/11/28 17:02:56 | 000,557,056 | ---- | M] () -- c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
MOD - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2008/09/11 09:00:05 | 000,168,960 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\unrar.dll
MOD - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
MOD - [2008/04/14 11:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\msdmo.dll
MOD - [2008/04/14 11:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\SYSTEM32\devenum.dll
MOD - [2008/01/23 10:45:18 | 000,310,616 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libssl32.dll
MOD - [2008/01/23 10:45:16 | 001,527,751 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libeay32.dll
MOD - [2007/04/05 11:27:06 | 000,007,680 | ---- | M] () -- D:\DAEMON Tools\Plugins\Images\bw5mount.dll
MOD - [2005/10/01 20:00:03 | 000,610,304 | ---- | M] () -- c:\windows\assembly\gac\hpodmres\3.0.0.0__a53cf5803f4c3827\hpodmres.dll
MOD - [2005/10/01 20:00:03 | 000,005,120 | ---- | M] () -- c:\windows\assembly\gac\hpodmres.resources\3.0.0.0_en_a53cf5803f4c3827\hpodmres.resources.dll
MOD - [2005/10/01 19:56:19 | 000,430,080 | ---- | M] () -- c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll
MOD - [2005/10/01 19:56:19 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2005/10/01 19:56:15 | 000,010,240 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2005/10/01 19:56:14 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2005/04/22 19:17:18 | 000,010,752 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/12/23 18:47:36 | 000,069,632 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2004/09/07 19:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
MOD - [2004/08/10 16:11:12 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2004/08/10 16:11:10 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2004/08/10 16:11:10 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2004/08/10 16:11:08 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2004/08/10 16:09:42 | 000,007,680 | ---- | M] () -- c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2003/07/30 00:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
SRV - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2006/11/06 15:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\HPZipm12.exe -- (Pml Driver HPZ12)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/11/29 04:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/29 04:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/29 04:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/29 04:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/29 04:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/29 04:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/29 04:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/05/12 00:38:32 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/04/14 05:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/24 08:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tapvpn.sys -- (tapvpn)
DRV - [2007/08/01 23:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/06/25 20:40:19 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2004/12/04 00:34:26 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/16 13:03:52 | 000,108,791 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/21 18:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys -- (w29n51) Intel(R)
DRV - [2004/10/08 12:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/21 11:55:20 | 000,084,512 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdm.sys -- (ssm_mdm)
DRV - [2004/09/21 11:55:20 | 000,006,096 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2004/09/21 11:55:18 | 000,052,416 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_bus.sys -- (ssm_bus) Samsung Mobile USB Device II 1.0 driver (WDM)
DRV - [2004/09/15 22:53:12 | 000,271,704 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys -- (STAC97)
DRV - [2004/08/31 11:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2004/08/18 17:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/12 11:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys -- (IWCA)
DRV - [2004/08/04 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/08/04 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/06/17 18:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 18:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 18:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2004/05/26 18:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/02/13 13:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/09/16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001/07/03 16:47:02 | 000,103,792 | ---- | M] (STMicroelectronics                                          ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\STV672.sys -- (STV672)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@xmlauthor.com/downloads: C:\WINDOWS\system32\npmirage.dll (XMLAuthor Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Basti\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/05 14:36:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/05 14:36:06 | 000,000,000 | ---D | M]
 
[2009/01/17 18:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Extensions
[2012/02/05 14:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions
[2010/09/29 10:00:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/29 10:00:01 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2012/02/05 14:40:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\BASTI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5C7HAZPN.DEFAULT\EXTENSIONS\{FCAB6FDD-5585-425B-95C1-5ED856F3FD08}.XPI
[2012/01/30 03:13:13 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/03 23:06:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2012/01/30 01:08:59 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 00:50:55 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/30 01:08:59 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/30 01:08:59 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/30 01:08:59 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2012/02/04 11:12:09 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - No CLSID value found.
O2 - BHO: (PaltalkWebLogin) - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll (AVM Software Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKCU..\Run: [DAEMON Tools] D:\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Timezone] C:\Program Files\Microsoft Time Zone\TimeZone.exe (Microsoft)
O4 - HKLM..\RunOnce: [Installing-ie8] C:\WINDOWS\TEMP\IE8-WindowsXP-x86-ENU.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe (Headlight Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://D:\FlashCapture\fciext.dll/FCIEXT.htm File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www4.snapfish.com.au/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{224F3BDC-E16C-483D-9088-91290CED9ABA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 16:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/10/17 19:38:57 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007/09/28 19:42:02 | 000,002,292 | ---- | M] () - C:\autorun.PNF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/02/08 22:54:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\WEYTCache
[2012/02/08 22:52:51 | 002,631,168 | ---- | C] (MySQL AB) -- C:\WINDOWS\System32\myodbc5.dll
[2012/02/08 22:52:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Worship Extreme
[2012/02/08 22:24:30 | 000,000,000 | ---D | C] -- C:\Program Files\CrossWire
[2012/02/07 20:18:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Softouch
[2012/02/07 20:18:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Borland Shared
[2012/02/07 20:18:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Application Data\Softouch
[2012/02/07 20:18:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Softouch
[2012/02/05 22:47:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012/02/05 22:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Desktop\Dial-a-fix-v0.60.0.24
[2012/02/05 22:27:40 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2012/02/05 22:27:35 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2012/02/05 22:27:24 | 000,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xrxflnch.exe
[2012/02/05 22:27:14 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe
[2012/02/05 22:27:09 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2012/02/05 22:27:07 | 000,019,455 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wvchntxx.sys
[2012/02/05 22:27:03 | 000,012,063 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wsiintxx.sys
[2012/02/05 22:26:46 | 000,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2012/02/05 22:26:37 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2012/02/05 22:26:32 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2012/02/05 22:26:21 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys
[2012/02/05 22:26:15 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiamsmud.dll
[2012/02/05 22:26:10 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wiafbdrv.dll
[2012/02/05 22:26:09 | 000,041,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.dll
[2012/02/05 22:26:09 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.sys
[2012/02/05 22:26:02 | 000,701,386 | ---- | C] (3Com Corporation) -- C:\WINDOWS\System32\dllcache\wdhaalba.sys
[2012/02/05 22:26:01 | 000,023,615 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wch7xxnt.sys
[2012/02/05 22:26:00 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wceusbsh.sys
[2012/02/05 22:25:55 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2012/02/05 22:25:52 | 000,033,599 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv04nt.sys
[2012/02/05 22:25:50 | 000,019,551 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv02nt.sys
[2012/02/05 22:25:49 | 000,029,311 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\watv01nt.sys
[2012/02/05 22:25:48 | 000,011,775 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv05nt.sys
[2012/02/05 22:25:46 | 000,012,127 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv02nt.sys
[2012/02/05 22:25:45 | 000,012,415 | ---- | C] (Intel(R) Corporation) -- C:\WINDOWS\System32\dllcache\wadv01nt.sys
[2012/02/05 22:25:40 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2012/02/05 22:25:35 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2012/02/05 22:25:30 | 000,048,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w32.dll
[2012/02/05 22:25:30 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2012/02/05 22:25:24 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys
[2012/02/05 22:25:19 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys
[2012/02/05 22:25:14 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys
[2012/02/05 22:25:09 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys
[2012/02/05 22:25:04 | 000,024,576 | ---- | C] (VIA Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\viairda.sys
[2012/02/05 22:24:57 | 000,687,999 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrwdxjs.sys
[2012/02/05 22:24:52 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys
[2012/02/05 22:24:46 | 000,113,762 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usrpda.sys
[2012/02/05 22:24:42 | 000,007,556 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usroslba.sys
[2012/02/05 22:24:36 | 000,224,802 | ---- | C] (U.S. Robotics Corporation) -- C:\WINDOWS\System32\dllcache\usr1807a.sys
[2012/02/05 22:24:31 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys
[2012/02/05 22:24:27 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys
[2012/02/05 22:24:22 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys
[2012/02/05 22:24:20 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbser.sys
[2012/02/05 22:24:18 | 000,017,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbohci.sys
[2012/02/05 22:24:16 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2012/02/05 22:24:14 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2012/02/05 22:24:07 | 000,094,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxud32.dll
[2012/02/05 22:24:03 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu40.dll
[2012/02/05 22:23:58 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu22.dll
[2012/02/05 22:23:54 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxu12.dll
[2012/02/05 22:23:49 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2012/02/05 22:23:45 | 000,022,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxpcls.sys
[2012/02/05 22:23:41 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxp60.dll
[2012/02/05 22:23:36 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\umaxcam.dll
[2012/02/05 22:23:32 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2012/02/05 22:23:27 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2012/02/05 22:23:22 | 000,011,520 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\twotrack.sys
[2012/02/05 22:23:21 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsprof.exe
[2012/02/05 22:23:14 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2012/02/05 22:23:10 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2012/02/05 22:23:05 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2012/02/05 22:23:01 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2012/02/05 22:22:56 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2012/02/05 22:22:52 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2012/02/05 22:22:47 | 000,034,375 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\dllcache\tpro4.sys
[2012/02/05 22:22:43 | 000,042,496 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4res.dll
[2012/02/05 22:22:42 | 000,082,944 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4mon.exe
[2012/02/05 22:22:37 | 000,031,744 | ---- | C] (IBM Corporation) -- C:\WINDOWS\System32\dllcache\tp4.dll
[2012/02/05 22:22:31 | 000,230,912 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd03.sys
[2012/02/05 22:22:27 | 000,241,664 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tosdvd02.sys
[2012/02/05 22:22:22 | 000,028,232 | ---- | C] (TOSHIBA Corporation) -- C:\WINDOWS\System32\dllcache\tos4mo.sys
[2012/02/05 22:22:17 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys
[2012/02/05 22:22:11 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2012/02/05 22:22:07 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2012/02/05 22:22:05 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2012/02/05 22:22:04 | 000,019,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdspx.sys
[2012/02/05 22:22:00 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2012/02/05 22:21:55 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2012/02/05 22:21:55 | 000,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdipx.sys
[2012/02/05 22:21:54 | 000,013,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdasync.sys
[2012/02/05 22:21:48 | 000,030,464 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\dllcache\tbatm155.sys
[2012/02/05 22:21:43 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tandqic.sys
[2012/02/05 22:21:39 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2012/02/05 22:21:35 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2012/02/05 22:21:27 | 000,094,293 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sxports.dll
[2012/02/05 22:21:23 | 000,103,936 | ---- | C] (Perle Systems Ltd. ) -- C:\WINDOWS\System32\dllcache\sx.sys
[2012/02/05 22:21:19 | 000,003,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swusbflt.sys
[2012/02/05 22:21:15 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpidflt.dll
[2012/02/05 22:21:11 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swpdflt2.dll
[2012/02/05 22:21:06 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_wheel.dll
[2012/02/05 22:21:02 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sw_effct.dll
[2012/02/05 22:20:57 | 000,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll
[2012/02/05 22:20:53 | 000,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll
[2012/02/05 22:20:49 | 000,285,760 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys
[2012/02/05 22:20:44 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2012/02/05 22:20:38 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2012/02/05 22:20:33 | 000,099,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusd.dll
[2012/02/05 22:20:32 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusbusd.dll
[2012/02/05 22:20:25 | 000,024,660 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxupchk.dll
[2012/02/05 22:20:19 | 000,061,824 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\speed.sys
[2012/02/05 22:20:15 | 000,106,584 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spdports.dll
[2012/02/05 22:20:11 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2012/02/05 22:20:07 | 000,037,040 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.sys
[2012/02/05 22:20:03 | 000,114,688 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypi.dll
[2012/02/05 22:19:59 | 000,020,752 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonync.sys
[2012/02/05 22:19:54 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonymc.sys
[2012/02/05 22:19:53 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sonyait.sys
[2012/02/05 22:19:52 | 000,143,422 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\softkey.dll
[2012/02/05 22:19:47 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2012/02/05 22:19:47 | 000,007,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snyaitmc.sys
[2012/02/05 22:19:46 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpstup.dll
[2012/02/05 22:19:43 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2012/02/05 22:19:42 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smimsgif.dll
[2012/02/05 22:19:39 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2012/02/05 22:19:38 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsm.dll
[2012/02/05 22:19:38 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsy.dll
[2012/02/05 22:19:34 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2012/02/05 22:19:30 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2012/02/05 22:19:26 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2012/02/05 22:19:22 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2012/02/05 22:19:17 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbhc.sys
[2012/02/05 22:19:16 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbclass.sys
[2012/02/05 22:19:15 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb6w.dll
[2012/02/05 22:19:15 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smbbatt.sys
[2012/02/05 22:19:11 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb3w.dll
[2012/02/05 22:19:06 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb0w.dll
[2012/02/05 22:19:06 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma3w.dll
[2012/02/05 22:19:02 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm9aw.dll
[2012/02/05 22:19:02 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma0w.dll
[2012/02/05 22:19:01 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm93w.dll
[2012/02/05 22:19:01 | 000,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm92w.dll
[2012/02/05 22:18:57 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm91w.dll
[2012/02/05 22:18:57 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm90w.dll
[2012/02/05 22:18:57 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8dw.dll
[2012/02/05 22:18:56 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8cw.dll
[2012/02/05 22:18:56 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8aw.dll
[2012/02/05 22:18:56 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm89w.dll
[2012/02/05 22:18:55 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm87w.dll
[2012/02/05 22:18:55 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm81w.dll
[2012/02/05 22:18:54 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm59w.dll
[2012/02/05 22:18:52 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2012/02/05 22:18:48 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2012/02/05 22:18:44 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2012/02/05 22:18:40 | 000,157,696 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv256.dll
[2012/02/05 22:18:36 | 000,050,432 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisv.sys
[2012/02/05 22:18:35 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2012/02/05 22:18:31 | 000,238,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll
[2012/02/05 22:18:27 | 000,104,064 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys
[2012/02/05 22:18:22 | 000,150,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306v.dll
[2012/02/05 22:18:19 | 000,068,608 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis6306p.sys
[2012/02/05 22:18:13 | 000,252,032 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300iv.dll
[2012/02/05 22:18:09 | 000,101,760 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sis300ip.sys
[2012/02/05 22:18:09 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\simptcp.dll
[2012/02/05 22:17:58 | 000,161,568 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2012/02/05 22:17:54 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys
[2012/02/05 22:17:50 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2012/02/05 22:17:46 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2012/02/05 22:17:42 | 000,036,480 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sfmanm.sys
[2012/02/05 22:17:35 | 000,006,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\serscan.sys
[2012/02/05 22:17:31 | 000,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2012/02/05 22:17:31 | 000,017,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sermouse.sys
[2012/02/05 22:17:26 | 000,006,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seaddsmc.sys
[2012/02/05 22:17:25 | 000,011,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiscan.sys
[2012/02/05 22:17:21 | 000,011,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scsiprnt.sys
[2012/02/05 22:17:20 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2012/02/05 22:17:16 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2012/02/05 22:17:12 | 000,016,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scmstcs.sys
[2012/02/05 22:17:08 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2012/02/05 22:17:04 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2012/02/05 22:17:02 | 000,043,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sbp2port.sys
[2012/02/05 22:16:58 | 000,495,616 | ---- | C] (Creative Technology Ltd.) -- C:\WINDOWS\System32\dllcache\sblfx.dll
[2012/02/05 22:16:52 | 000,075,392 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmxm.sys
[2012/02/05 22:16:48 | 000,245,632 | ---- | C] (S3 Graphics, Inc.) -- C:\WINDOWS\System32\dllcache\s3savmx.dll
[2012/02/05 22:16:44 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2012/02/05 22:16:41 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2012/02/05 22:16:37 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2012/02/05 22:16:33 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2012/02/05 22:16:29 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2012/02/05 22:16:25 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2012/02/05 22:16:21 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2012/02/05 22:16:17 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2012/02/05 22:16:13 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys
[2012/02/05 22:16:10 | 000,065,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\s3legacy.sys
[2012/02/05 22:16:05 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2012/02/05 22:16:01 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2012/02/05 22:16:00 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDO

11
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 08, 2012, 02:35:48 AM »
Hi guestolo

Sorry its taken me a few days to reply. I have followed all your instructions.

The laptop still seems to run slow but i am wondering if it may be because i have so many prgrams starting now everytime I boot as we removed the custom boot up. Im not sure how much it would speed it up putting the custom option back on.

Thanks so much for your help!


12
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 05, 2012, 01:40:53 AM »
Hi guestolo

My bad about changing the start up, I have changed it back as you asked.

Please find below latest OTL log

OTL logfile created on: 5/02/2012 5:32:35 PM - Run 5
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 526.59 Mb Available Physical Memory | 51.46% Memory free
2.40 Gb Paging File | 1.86 Gb Available in Paging File | 77.36% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 3.21 Gb Free Space | 9.39% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 3.58 Gb Free Space | 8.89% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
PRC - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/07/26 00:26:20 | 000,528,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/11/15 07:28:59 | 011,376,640 | ---- | M] (AVM Software Inc.) -- C:\Program Files\Paltalk Messenger\paltalk.exe
PRC - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
PRC - [2007/04/04 09:29:15 | 000,165,784 | ---- | M] (DT Soft Ltd.) -- D:\DAEMON Tools\daemon.exe
PRC - [2006/10/26 23:59:25 | 000,030,720 | ---- | M] () -- C:\Program Files\Paltalk Messenger\palstart.exe
PRC - [2006/06/13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE
PRC - [2005/02/23 12:05:52 | 002,301,952 | ---- | M] (Headlight Software, Inc.) -- C:\Program Files\GetRight\getright.exe
PRC - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/10/30 17:59:54 | 000,385,024 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2004/10/19 13:01:52 | 000,712,704 | ---- | M] (Microsoft) -- C:\Program Files\Microsoft Time Zone\TimeZone.exe
PRC - [2004/09/13 14:33:20 | 000,155,648 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004/09/07 19:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004/09/07 19:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
PRC - [2004/08/19 12:40:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2004/01/07 04:01:00 | 000,110,592 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
PRC - [2002/01/11 14:25:54 | 000,303,104 | ---- | M] (Zabaware, Inc.) -- D:\HalReader\HalReader.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/02/05 04:03:47 | 001,689,088 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020401\algo.dll
MOD - [2012/01/22 15:44:10 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b8c4ae52\mscorlib.dll
MOD - [2012/01/22 15:44:05 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cded7d4c\system.drawing.dll
MOD - [2012/01/22 15:43:41 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_f66f41a6\system.xml.dll
MOD - [2012/01/22 15:43:16 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_0ae88b83\system.windows.forms.dll
MOD - [2012/01/22 15:40:19 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0a4d6360\system.dll
MOD - [2012/01/18 01:32:25 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/18 01:32:23 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2011/11/04 02:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\SYSTEM32\quartz.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 00:27:01 | 001,640,216 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Resources.dll
MOD - [2011/07/26 00:26:57 | 000,256,424 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/11/28 17:09:04 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2009/11/28 17:09:04 | 000,006,656 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2009/11/28 17:09:01 | 000,614,400 | ---- | M] () -- c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
MOD - [2009/11/28 17:07:34 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2009/11/28 17:06:42 | 000,249,856 | ---- | M] () -- c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2009/11/28 17:06:42 | 000,045,056 | ---- | M] () -- c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2009/11/28 17:06:41 | 000,368,640 | ---- | M] () -- c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2009/11/28 17:06:41 | 000,163,840 | ---- | M] () -- c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2009/11/28 17:06:41 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2009/11/28 17:06:41 | 000,007,168 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2009/11/28 17:06:40 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
MOD - [2009/11/28 17:06:40 | 000,028,672 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2009/11/28 17:06:40 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2009/11/28 17:02:58 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
MOD - [2009/11/28 17:02:57 | 000,192,512 | ---- | M] () -- c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
MOD - [2009/11/28 17:02:57 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2009/11/28 17:02:57 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
MOD - [2009/11/28 17:02:56 | 000,557,056 | ---- | M] () -- c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
MOD - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2008/11/15 07:11:52 | 000,044,032 | ---- | M] () -- C:\Program Files\Paltalk Messenger\ctrlkey.dll
MOD - [2008/09/11 09:00:05 | 000,168,960 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\unrar.dll
MOD - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
MOD - [2008/04/14 11:12:03 | 000,192,512 | ---- | M] () -- C:\WINDOWS\SYSTEM32\qcap.dll
MOD - [2008/04/14 11:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\msdmo.dll
MOD - [2008/04/14 11:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\SYSTEM32\devenum.dll
MOD - [2008/01/23 10:45:18 | 000,310,616 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libssl32.dll
MOD - [2008/01/23 10:45:16 | 001,527,751 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libeay32.dll
MOD - [2007/04/05 11:27:06 | 000,007,680 | ---- | M] () -- D:\DAEMON Tools\Plugins\Images\bw5mount.dll
MOD - [2006/10/26 23:59:25 | 000,030,720 | ---- | M] () -- C:\Program Files\Paltalk Messenger\palstart.exe
MOD - [2005/10/01 20:00:03 | 000,610,304 | ---- | M] () -- c:\windows\assembly\gac\hpodmres\3.0.0.0__a53cf5803f4c3827\hpodmres.dll
MOD - [2005/10/01 20:00:03 | 000,005,120 | ---- | M] () -- c:\windows\assembly\gac\hpodmres.resources\3.0.0.0_en_a53cf5803f4c3827\hpodmres.resources.dll
MOD - [2005/10/01 19:56:19 | 000,430,080 | ---- | M] () -- c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll
MOD - [2005/10/01 19:56:19 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2005/10/01 19:56:15 | 000,010,240 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2005/10/01 19:56:14 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2005/04/22 19:17:18 | 000,010,752 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/12/23 18:47:36 | 000,069,632 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2004/09/07 19:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
MOD - [2004/08/10 16:11:12 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2004/08/10 16:11:10 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2004/08/10 16:11:10 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2004/08/10 16:11:08 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2004/08/10 16:09:42 | 000,007,680 | ---- | M] () -- c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2003/07/30 00:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
SRV - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2006/11/06 15:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\HPZipm12.exe -- (Pml Driver HPZ12)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/11/29 04:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/29 04:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/29 04:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/29 04:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/29 04:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/29 04:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/29 04:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/05/12 00:38:32 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/04/14 05:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/24 08:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tapvpn.sys -- (tapvpn)
DRV - [2007/08/01 23:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/06/25 20:40:19 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2004/12/04 00:34:26 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/16 13:03:52 | 000,108,791 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/21 18:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys -- (w29n51) Intel(R)
DRV - [2004/10/08 12:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/21 11:55:20 | 000,084,512 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdm.sys -- (ssm_mdm)
DRV - [2004/09/21 11:55:20 | 000,006,096 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2004/09/21 11:55:18 | 000,052,416 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_bus.sys -- (ssm_bus) Samsung Mobile USB Device II 1.0 driver (WDM)
DRV - [2004/09/15 22:53:12 | 000,271,704 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys -- (STAC97)
DRV - [2004/08/31 11:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2004/08/18 17:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/12 11:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys -- (IWCA)
DRV - [2004/08/04 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/08/04 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/06/17 18:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 18:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 18:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2004/05/26 18:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/02/13 13:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/09/16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001/07/03 16:47:02 | 000,103,792 | ---- | M] (STMicroelectronics                                          ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\STV672.sys -- (STV672)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@xmlauthor.com/downloads: C:\WINDOWS\system32\npmirage.dll (XMLAuthor Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Basti\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/05 14:36:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/05 14:36:06 | 000,000,000 | ---D | M]
 
[2009/01/17 18:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Extensions
[2012/02/05 14:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions
[2010/09/29 10:00:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/29 10:00:01 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2012/02/05 14:40:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\BASTI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5C7HAZPN.DEFAULT\EXTENSIONS\{FCAB6FDD-5585-425B-95C1-5ED856F3FD08}.XPI
[2012/01/30 03:13:13 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/03 23:06:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2012/01/30 01:08:59 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/01/30 00:50:55 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/30 01:08:59 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/01/30 01:08:59 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/01/30 01:08:59 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2012/02/04 11:12:09 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - No CLSID value found.
O2 - BHO: (PaltalkWebLogin) - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll (AVM Software Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [DAEMON Tools] D:\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Timezone] C:\Program Files\Microsoft Time Zone\TimeZone.exe (Microsoft)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe (Headlight Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk = C:\Program Files\Paltalk Messenger\palstart.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk = C:\WINDOWS\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe (InstallShield Software Corp.)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://D:\FlashCapture\fciext.dll/FCIEXT.htm File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www4.snapfish.com.au/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{224F3BDC-E16C-483D-9088-91290CED9ABA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 16:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/10/17 19:38:57 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007/09/28 19:42:02 | 000,002,292 | ---- | M] () - C:\autorun.PNF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/02/05 15:13:34 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/02/04 10:45:22 | 004,394,794 | R--- | C] (Swearware) -- C:\Documents and Settings\Basti\Desktop\ComboFix.exe
[2012/02/04 10:40:51 | 002,059,312 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Basti\Desktop\tdsskiller.exe
[2012/02/03 23:55:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/03 23:55:10 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/03 23:55:10 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/03 23:21:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/03 22:49:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012/02/03 22:45:45 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/01/31 18:51:07 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Start Menu\Programs\HiJackThis
[2012/01/22 22:18:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Any Video Converter
[2012/01/18 01:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Aimersoft DVD Ripper
[2012/01/18 01:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Aimersoft
[2012/01/18 01:00:23 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\WINDOWS\System32\iconv.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012/02/05 17:23:19 | 000,002,191 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk
[2012/02/05 17:21:22 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2012/02/05 17:19:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2012/02/05 17:19:24 | 1073,152,000 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 17:13:51 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2012/02/05 14:36:20 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\Basti\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/05 14:36:20 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/02/04 11:12:09 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2012/02/04 10:45:23 | 004,394,794 | R--- | M] (Swearware) -- C:\Documents and Settings\Basti\Desktop\ComboFix.exe
[2012/02/04 10:40:56 | 002,059,312 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Basti\Desktop\tdsskiller.exe
[2012/02/03 22:48:45 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/02/03 22:45:45 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/02/02 20:02:05 | 000,099,328 | ---- | M] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/02 20:01:56 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 17:39:17 | 000,015,232 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/18 01:31:22 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/17 18:57:36 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/17 18:32:44 | 000,446,424 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2012/01/17 18:32:44 | 000,073,464 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2012/01/17 17:47:25 | 000,831,743 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:06 | 022,328,992 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
 
========== Files Created - No Company Name ==========
 
[2012/02/05 17:13:48 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/05 17:13:48 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
[2012/02/05 17:13:48 | 000,000,694 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk
[2012/02/05 17:13:48 | 000,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2012/02/05 17:13:47 | 000,002,191 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk
[2012/02/05 17:13:47 | 000,001,571 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
[2012/02/05 17:13:47 | 000,001,570 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
[2012/02/05 17:13:47 | 000,000,988 | ---- | C] () -- C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2012/02/05 17:13:47 | 000,000,853 | ---- | C] () -- C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
[2012/02/05 14:36:19 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/04 10:49:33 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/04 10:49:33 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/03 22:48:45 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/02/03 22:48:45 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/31 17:39:17 | 000,015,232 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/17 17:47:24 | 000,831,743 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:04 | 022,328,992 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[2010/08/26 02:05:48 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\winscp.rnd
[2010/08/07 18:05:27 | 000,073,684 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/06/05 20:50:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/28 16:16:24 | 000,104,182 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2009/11/28 16:16:24 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2009/05/08 11:13:04 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 23:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/04/30 17:00:12 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/02/22 15:45:42 | 000,641,021 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2009/02/22 15:45:42 | 000,187,904 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2009/02/22 15:45:42 | 000,166,912 | ---- | C] () -- C:\WINDOWS\System32\Lame_enc.dll
[2009/02/22 15:45:42 | 000,002,890 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/01/31 18:51:04 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/28 11:04:01 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/28 11:04:00 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/28 11:03:59 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/27 19:01:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/27 19:01:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/27 19:01:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/22 07:09:03 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/01/17 18:30:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/10/01 22:41:06 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/10/01 22:41:06 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/10/01 22:41:06 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/10/01 22:41:06 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/10/01 18:36:23 | 000,000,074 | -H-- | C] () -- C:\WINDOWS\uce.dat
[2008/07/03 01:43:26 | 000,013,805 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/03 01:42:59 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/04/30 23:28:31 | 000,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008/04/30 23:28:31 | 000,066,560 | ---- | C] () -- C:\WINDOWS\MOTA113.exe
[2008/04/30 23:28:31 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008/04/30 23:28:30 | 000,502,784 | ---- | C] () -- C:\WINDOWS\x2.64.exe
[2008/04/30 23:28:30 | 000,240,128 | ---- | C] () -- C:\WINDOWS\System32\x.264.exe
[2008/04/30 23:28:30 | 000,217,073 | ---- | C] () -- C:\WINDOWS\meta4.exe
[2008/01/04 08:11:11 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/13 14:40:54 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2007/02/22 11:13:50 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/29 18:18:33 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/02/27 22:22:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CompanionApp.INI
[2006/02/27 22:19:44 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\$_hpcst$.hpc
[2006/01/28 12:31:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/10/26 17:03:16 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/10/26 16:59:36 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/08/22 11:16:29 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\p.dat
[2005/08/22 11:15:48 | 000,129,822 | ---- | C] () -- C:\WINDOWS\System32\system.dat
[2005/06/18 18:13:39 | 000,099,328 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/05/25 08:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005/05/06 12:36:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\fusioncache.dat
[2005/05/06 12:17:14 | 000,000,300 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/05/06 12:16:49 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2005/05/06 12:16:44 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2005/05/06 11:51:35 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\instlsp.exe
[2005/05/05 20:52:49 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/04/28 15:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/28 15:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/28 15:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/04/25 17:05:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/04/25 17:03:17 | 000,000,344 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/04/25 16:59:24 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/04/25 16:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2005/04/25 16:45:06 | 000,446,424 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2005/04/25 16:45:06 | 000,073,464 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2005/04/25 16:36:32 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/12/20 11:08:28 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/10/15 21:56:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/12 11:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2004/08/10 16:13:12 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 16:08:08 | 000,341,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 16:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 16:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 13:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 19:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1999/07/23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1996/02/24 08:34:48 | 000,014,629 | ---- | C] () -- C:\WINDOWS\System32\Declw.dll
[1996/02/23 06:09:20 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\Decln.dll
[1980/01/01 03:00:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
 
========== LOP Check ==========
 
[2009/08/01 16:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3DVIA
[2010/05/22 16:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/01/07 19:09:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2009/10/25 15:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/11/11 14:42:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2009/08/22 10:47:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/04/29 13:31:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/08/21 22:08:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/08/21 22:15:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
[2008/10/01 18:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/08/21 22:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VideoSpin
[2009/01/18 01:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/11/06 23:37:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/08/06 21:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/26 21:22:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/01/21 23:24:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/04/28 05:43:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/07/21 22:53:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\3DMaker
[2009/09/27 20:30:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Any Video Converter
[2009/08/23 12:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Audacity
[2011/11/24 22:09:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Azureus
[2005/08/22 10:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Block Checker
[2012/02/03 18:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Dropbox
[2007/11/11 14:42:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\eBay
[2010/06/06 22:39:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Facebook
[2009/07/25 20:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\GrabPro
[2010/08/19 23:12:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\HandBrake
[2005/05/05 21:04:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Leadertech
[2007/03/11 17:01:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\My Pictures 3D
[2009/08/22 10:46:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\NCH Swift Sound
[2007/04/29 13:31:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Nokia
[2009/09/04 23:03:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\OpenArena
[2008/04/27 12:40:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Opera
[2012/02/03 18:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Orbit
[2008/02/26 13:38:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Paltalk
[2007/09/28 19:44:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\PC Suite
[2009/02/26 18:49:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Red Kawa
[2010/05/30 17:27:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\SharePod
[2006/04/15 17:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\SlySoft
[2008/12/27 18:26:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Snapfish
[2010/05/20 21:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\TeamViewer
[2005/05/06 18:45:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Template
[2008/10/01 18:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Ulead Systems
[2006/12/26 22:45:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\VoipDiscount
[2009/09/04 21:19:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Warsow 0.5
[2007/01/03 11:23:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\WholeSecurity
[2010/11/06 23:38:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\WindSolutions
[2010/07/21 22:37:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Zoner
[2011/11/09 23:25:30 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
 
========== Purity Check ==========
 
 

< End of report >



13
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 04, 2012, 11:09:40 PM »
Hi guestolo

Here is the latest OTL log:

OTL logfile created on: 5/02/2012 1:59:01 PM - Run 4
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 601.35 Mb Available Physical Memory | 58.76% Memory free
2.40 Gb Paging File | 1.88 Gb Available in Paging File | 78.41% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 3.23 Gb Free Space | 9.45% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 3.58 Gb Free Space | 8.89% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
PRC - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/07/26 00:26:20 | 000,528,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/11/15 07:28:59 | 011,376,640 | ---- | M] (AVM Software Inc.) -- C:\Program Files\Paltalk Messenger\paltalk.exe
PRC - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/11/22 12:49:08 | 000,385,024 | ---- | M] (Sony Corporation) -- D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
PRC - [2007/04/04 09:29:15 | 000,165,784 | ---- | M] (DT Soft Ltd.) -- D:\DAEMON Tools\daemon.exe
PRC - [2006/10/26 23:59:25 | 000,030,720 | ---- | M] () -- C:\Program Files\Paltalk Messenger\palstart.exe
PRC - [2006/09/29 18:15:36 | 000,185,784 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2006/06/13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE
PRC - [2005/05/05 07:40:15 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
PRC - [2005/02/23 12:05:52 | 002,301,952 | ---- | M] (Headlight Software, Inc.) -- C:\Program Files\GetRight\getright.exe
PRC - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/12/17 10:00:00 | 000,118,784 | ---- | M] (WinZip Computing, Inc.) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2004/10/30 17:59:54 | 000,385,024 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2004/10/19 13:01:52 | 000,712,704 | ---- | M] (Microsoft) -- C:\Program Files\Microsoft Time Zone\TimeZone.exe
PRC - [2004/09/13 14:33:20 | 000,155,648 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004/09/07 19:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004/09/07 19:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
PRC - [2004/08/19 12:40:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2002/01/11 14:25:54 | 000,303,104 | ---- | M] (Zabaware, Inc.) -- D:\HalReader\HalReader.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/02/05 04:03:47 | 001,689,088 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020401\algo.dll
MOD - [2012/01/22 15:44:10 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_b8c4ae52\mscorlib.dll
MOD - [2012/01/22 15:44:05 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_cded7d4c\system.drawing.dll
MOD - [2012/01/22 15:43:41 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_f66f41a6\system.xml.dll
MOD - [2012/01/22 15:43:16 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_0ae88b83\system.windows.forms.dll
MOD - [2012/01/22 15:40:19 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_0a4d6360\system.dll
MOD - [2012/01/18 01:32:25 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/18 01:32:23 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2011/11/04 02:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\SYSTEM32\quartz.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 00:27:01 | 001,640,216 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Resources.dll
MOD - [2011/07/26 00:26:57 | 000,256,424 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/11/28 17:09:04 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2009/11/28 17:09:04 | 000,006,656 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2009/11/28 17:09:01 | 000,614,400 | ---- | M] () -- c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
MOD - [2009/11/28 17:07:34 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2009/11/28 17:06:42 | 000,249,856 | ---- | M] () -- c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2009/11/28 17:06:42 | 000,045,056 | ---- | M] () -- c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2009/11/28 17:06:41 | 000,368,640 | ---- | M] () -- c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2009/11/28 17:06:41 | 000,163,840 | ---- | M] () -- c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2009/11/28 17:06:41 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2009/11/28 17:06:41 | 000,007,168 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2009/11/28 17:06:40 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
MOD - [2009/11/28 17:06:40 | 000,028,672 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2009/11/28 17:06:40 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2009/11/28 17:02:58 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
MOD - [2009/11/28 17:02:57 | 000,192,512 | ---- | M] () -- c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
MOD - [2009/11/28 17:02:57 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2009/11/28 17:02:57 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
MOD - [2009/11/28 17:02:56 | 000,557,056 | ---- | M] () -- c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
MOD - [2009/05/08 11:35:50 | 002,780,432 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/05/08 11:34:08 | 000,559,888 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2008/11/15 07:11:52 | 000,044,032 | ---- | M] () -- C:\Program Files\Paltalk Messenger\ctrlkey.dll
MOD - [2008/09/11 09:00:05 | 000,168,960 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\unrar.dll
MOD - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
MOD - [2008/04/14 11:12:03 | 000,192,512 | ---- | M] () -- C:\WINDOWS\SYSTEM32\qcap.dll
MOD - [2008/04/14 11:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\msdmo.dll
MOD - [2008/04/14 11:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\SYSTEM32\devenum.dll
MOD - [2008/01/23 10:45:18 | 000,310,616 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libssl32.dll
MOD - [2008/01/23 10:45:16 | 001,527,751 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libeay32.dll
MOD - [2007/04/05 11:27:06 | 000,007,680 | ---- | M] () -- D:\DAEMON Tools\Plugins\Images\bw5mount.dll
MOD - [2006/10/26 23:59:25 | 000,030,720 | ---- | M] () -- C:\Program Files\Paltalk Messenger\palstart.exe
MOD - [2005/10/01 20:00:03 | 000,610,304 | ---- | M] () -- c:\windows\assembly\gac\hpodmres\3.0.0.0__a53cf5803f4c3827\hpodmres.dll
MOD - [2005/10/01 20:00:03 | 000,005,120 | ---- | M] () -- c:\windows\assembly\gac\hpodmres.resources\3.0.0.0_en_a53cf5803f4c3827\hpodmres.resources.dll
MOD - [2005/10/01 19:56:19 | 000,430,080 | ---- | M] () -- c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll
MOD - [2005/10/01 19:56:19 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll
MOD - [2005/10/01 19:56:19 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2005/10/01 19:56:15 | 000,010,240 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2005/10/01 19:56:14 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2005/05/05 07:40:15 | 000,030,720 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
MOD - [2005/04/22 19:17:18 | 000,010,752 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/12/23 18:47:36 | 000,069,632 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2004/09/07 19:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
MOD - [2004/08/10 16:11:12 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2004/08/10 16:11:10 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2004/08/10 16:11:10 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2004/08/10 16:11:08 | 000,299,008 | ---- | M] () -- c:\windows\assembly\gac\microsoft.visualbasic\7.0.5000.0__b03f5f7f11d50a3a\microsoft.visualbasic.dll
MOD - [2004/08/10 16:09:42 | 000,007,680 | ---- | M] () -- c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2003/07/30 00:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
SRV - [2011/11/29 05:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2006/11/06 15:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\HPZipm12.exe -- (Pml Driver HPZ12)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2011/11/29 04:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/29 04:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/29 04:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/29 04:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/29 04:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/29 04:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/29 04:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/05/12 00:38:32 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/04/14 05:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/24 08:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tapvpn.sys -- (tapvpn)
DRV - [2007/08/01 23:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/06/25 20:40:19 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2004/12/04 00:34:26 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/16 13:03:52 | 000,108,791 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/21 18:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys -- (w29n51) Intel(R)
DRV - [2004/10/08 12:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/21 11:55:20 | 000,084,512 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdm.sys -- (ssm_mdm)
DRV - [2004/09/21 11:55:20 | 000,006,096 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2004/09/21 11:55:18 | 000,052,416 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_bus.sys -- (ssm_bus) Samsung Mobile USB Device II 1.0 driver (WDM)
DRV - [2004/09/15 22:53:12 | 000,271,704 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys -- (STAC97)
DRV - [2004/08/31 11:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2004/08/18 17:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/12 11:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys -- (IWCA)
DRV - [2004/08/04 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/08/04 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/06/17 18:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 18:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 18:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2004/05/26 18:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/02/13 13:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/09/16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001/07/03 16:47:02 | 000,103,792 | ---- | M] (STMicroelectronics                                          ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\STV672.sys -- (STV672)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
 
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@xmlauthor.com/downloads: C:\WINDOWS\system32\npmirage.dll (XMLAuthor Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Basti\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/28 21:48:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/03 22:48:44 | 000,000,000 | ---D | M]
 
[2009/01/17 18:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Extensions
[2012/02/03 18:28:17 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions
[2010/09/29 10:00:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/21 15:10:25 | 000,000,000 | ---D | M] (Sothink Web Video Downloader for Firefox) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2010/09/29 10:00:01 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2010/09/29 10:00:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2012/02/03 23:06:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/02/03 23:06:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/02/03 23:06:25 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ORBITFF
[2012/02/03 23:06:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2011/06/16 20:20:36 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/06/16 20:20:36 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/06/16 20:20:36 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/06/16 20:20:36 | 000,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2012/02/04 11:12:09 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - No CLSID value found.
O2 - BHO: (PaltalkWebLogin) - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll (AVM Software Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [DAEMON Tools] D:\DAEMON Tools\daemon.exe (DT Soft Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Timezone] C:\Program Files\Microsoft Time Zone\TimeZone.exe (Microsoft)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe (Headlight Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk = C:\Program Files\Paltalk Messenger\palstart.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk = C:\WINDOWS\Installer\{96EF451E-A402-44D8-BAEE-D70D558A4122}\New_Shortcut_S1449_0EB7CDB78E0C4A918D2CA535D5B8160C.exe (InstallShield Software Corp.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Unwired Launchpad.lnk =  File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Unwired Launchpad.lnk =  File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://D:\FlashCapture\fciext.dll/FCIEXT.htm File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www4.snapfish.com.au/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{224F3BDC-E16C-483D-9088-91290CED9ABA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 16:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/10/17 19:38:57 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007/09/28 19:42:02 | 000,002,292 | ---- | M] () - C:\autorun.PNF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/02/04 10:45:22 | 004,394,794 | R--- | C] (Swearware) -- C:\Documents and Settings\Basti\Desktop\ComboFix.exe
[2012/02/04 10:40:51 | 002,059,312 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Basti\Desktop\tdsskiller.exe
[2012/02/03 23:55:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/03 23:55:10 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/03 23:55:10 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/03 23:21:38 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/03 22:49:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012/02/03 22:45:45 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/01/31 18:51:07 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Start Menu\Programs\HiJackThis
[2012/01/22 22:18:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Any Video Converter
[2012/01/18 01:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Aimersoft DVD Ripper
[2012/01/18 01:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Aimersoft
[2012/01/18 01:00:23 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\WINDOWS\System32\iconv.dll
 
========== Files - Modified Within 30 Days ==========
 
[2012/02/05 13:47:16 | 000,002,191 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk
[2012/02/05 13:44:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2012/02/05 13:42:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2012/02/05 13:42:05 | 1073,152,000 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 13:40:12 | 000,000,281 | RHS- | M] () -- C:\BOOT.INI
[2012/02/04 11:12:09 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\ETC\hosts
[2012/02/04 10:45:23 | 004,394,794 | R--- | M] (Swearware) -- C:\Documents and Settings\Basti\Desktop\ComboFix.exe
[2012/02/04 10:40:56 | 002,059,312 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\Basti\Desktop\tdsskiller.exe
[2012/02/03 22:48:45 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/02/03 22:45:45 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/02/02 20:02:05 | 000,099,328 | ---- | M] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/02 20:01:56 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 17:39:17 | 000,015,232 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/18 01:31:22 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/17 18:57:36 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/17 18:32:44 | 000,446,424 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2012/01/17 18:32:44 | 000,073,464 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2012/01/17 17:47:25 | 000,831,743 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:06 | 022,328,992 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
 
========== Files Created - No Company Name ==========
 
[2012/02/05 13:40:10 | 000,001,919 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
[2012/02/05 13:40:10 | 000,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2012/02/05 13:40:10 | 000,001,807 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
[2012/02/05 13:40:10 | 000,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2012/02/05 13:40:10 | 000,001,554 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2012/02/05 13:40:10 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
[2012/02/05 13:40:10 | 000,000,694 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk
[2012/02/05 13:40:09 | 000,030,720 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
[2012/02/05 13:40:09 | 000,002,191 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk
[2012/02/05 13:40:09 | 000,001,596 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Unwired Launchpad.lnk
[2012/02/05 13:40:09 | 000,001,571 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
[2012/02/05 13:40:09 | 000,001,570 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
[2012/02/05 13:40:09 | 000,001,518 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
[2012/02/05 13:40:09 | 000,000,988 | ---- | C] () -- C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2012/02/05 13:40:09 | 000,000,853 | ---- | C] () -- C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
[2012/02/05 13:40:08 | 000,001,692 | ---- | C] () -- C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Unwired Launchpad.lnk
[2012/02/04 10:49:33 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/02/04 10:49:33 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/02/03 22:48:45 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/02/03 22:48:45 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012/01/31 17:39:17 | 000,015,232 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/17 17:47:24 | 000,831,743 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:04 | 022,328,992 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[2010/08/26 02:05:48 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\winscp.rnd
[2010/08/07 18:05:27 | 000,073,684 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/06/05 20:50:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/28 16:16:24 | 000,104,182 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2009/11/28 16:16:24 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2009/05/08 11:13:04 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 23:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/04/30 17:00:12 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/02/22 15:45:42 | 000,641,021 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2009/02/22 15:45:42 | 000,187,904 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2009/02/22 15:45:42 | 000,166,912 | ---- | C] () -- C:\WINDOWS\System32\Lame_enc.dll
[2009/02/22 15:45:42 | 000,002,890 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/01/31 18:51:04 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/28 11:04:01 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/28 11:04:00 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/28 11:03:59 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/27 19:01:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/27 19:01:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/27 19:01:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/22 07:09:03 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/01/17 18:30:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/10/01 22:41:06 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/10/01 22:41:06 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/10/01 22:41:06 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/10/01 22:41:06 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/10/01 18:36:23 | 000,000,074 | -H-- | C] () -- C:\WINDOWS\uce.dat
[2008/07/03 01:43:26 | 000,013,805 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/03 01:42:59 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/04/30 23:28:31 | 000,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008/04/30 23:28:31 | 000,066,560 | ---- | C] () -- C:\WINDOWS\MOTA113.exe
[2008/04/30 23:28:31 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008/04/30 23:28:30 | 000,502,784 | ---- | C] () -- C:\WINDOWS\x2.64.exe
[2008/04/30 23:28:30 | 000,240,128 | ---- | C] () -- C:\WINDOWS\System32\x.264.exe
[2008/04/30 23:28:30 | 000,217,073 | ---- | C] () -- C:\WINDOWS\meta4.exe
[2008/01/04 08:11:11 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/13 14:40:54 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2007/02/22 11:13:50 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/29 18:18:33 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/02/27 22:22:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CompanionApp.INI
[2006/02/27 22:19:44 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\$_hpcst$.hpc
[2006/01/28 12:31:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/10/26 17:03:16 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/10/26 16:59:36 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/08/22 11:16:29 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\p.dat
[2005/08/22 11:15:48 | 000,129,822 | ---- | C] () -- C:\WINDOWS\System32\system.dat
[2005/06/18 18:13:39 | 000,099,328 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/05/25 08:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005/05/06 12:36:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\fusioncache.dat
[2005/05/06 12:17:14 | 000,000,300 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/05/06 12:16:49 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2005/05/06 12:16:44 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2005/05/06 11:51:35 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\instlsp.exe
[2005/05/05 20:52:49 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/04/28 15:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/28 15:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/28 15:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/04/25 17:05:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/04/25 17:03:17 | 000,000,344 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/04/25 16:59:24 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/04/25 16:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2005/04/25 16:45:06 | 000,446,424 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2005/04/25 16:45:06 | 000,073,464 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2005/04/25 16:36:32 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/12/20 11:08:28 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/10/15 21:56:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/12 11:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2004/08/10 16:13:12 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 16:08:08 | 000,341,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 16:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 16:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 13:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 19:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1999/07/23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1996/02/24 08:34:48 | 000,014,629 | ---- | C] () -- C:\WINDOWS\System32\Declw.dll
[1996/02/23 06:09:20 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\Decln.dll
[1980/01/01 03:00:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
 
========== LOP Check ==========
 
[2009/08/01 16:20:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3DVIA
[2010/05/22 16:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/01/07 19:09:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2009/10/25 15:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/11/11 14:42:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2009/08/22 10:47:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/04/29 13:31:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/08/21 22:08:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/08/21 22:15:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
[2008/10/01 18:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/08/21 22:11:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VideoSpin
[2005/06/15 10:55:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/01/18 01:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/11/06 23:37:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/08/06 21:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/26 21:22:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/01/21 23:24:27 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/04/28 05:43:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/07/21 22:53:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\3DMaker
[2009/09/27 20:30:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Any Video Converter
[2009/08/23 12:35:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Audacity
[2011/11/24 22:09:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Azureus
[2005/08/22 10:53:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Block Checker
[2012/02/03 18:52:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Dropbox
[2007/11/11 14:42:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\eBay
[2010/06/06 22:39:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\Facebook
[2009/07/25 20:47:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Basti\Application Data\GrabPro
[2010/08/19 23:12:01 | 000,000,000 | ---D | M] -- C:\D

14
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 03, 2012, 07:51:56 PM »
Hi guestolo

I followed all your instructions.

Please find the three loggs below, unfortuanetly firefox still doesnt open.

When I ran Combofix it never asked me about the Microsoft Windows Recovery Console  however did whatever it did and produced a logg at the end. Please find below:


10:41:35.0812 0964 TDSS rootkit removing tool 2.7.9.0 Feb  1 2012 09:28:49
10:41:37.0812 0964 ============================================================
10:41:37.0812 0964 Current date / time: 2012/02/04 10:41:37.0812
10:41:37.0812 0964 SystemInfo:
10:41:37.0812 0964
10:41:37.0812 0964 OS Version: 5.1.2600 ServicePack: 3.0
10:41:37.0812 0964 Product type: Workstation
10:41:37.0812 0964 ComputerName: D1JD5F1S
10:41:37.0812 0964 UserName: Basti
10:41:37.0812 0964 Windows directory: C:\WINDOWS
10:41:37.0812 0964 System windows directory: C:\WINDOWS
10:41:37.0812 0964 Processor architecture: Intel x86
10:41:37.0812 0964 Number of processors: 1
10:41:37.0812 0964 Page size: 0x1000
10:41:37.0812 0964 Boot type: Normal boot
10:41:37.0812 0964 ============================================================
10:41:39.0843 0964 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:41:39.0843 0964 \Device\Harddisk0\DR0:
10:41:39.0843 0964 MBR used
10:41:39.0843 0964 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x4477F35
10:41:39.0859 0964 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x44936BB, BlocksNum 0x507AE06
10:41:40.0078 0964 Initialize success
10:41:40.0078 0964 ============================================================
10:41:49.0406 0472 ============================================================
10:41:49.0406 0472 Scan started
10:41:49.0406 0472 Mode: Manual;
10:41:49.0406 0472 ============================================================
10:41:49.0781 0472 Aavmker4        (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys
10:41:49.0781 0472 Aavmker4 - ok
10:41:49.0843 0472 Abiosdsk - ok
10:41:49.0906 0472 abp480n5        (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:41:49.0906 0472 abp480n5 - ok
10:41:49.0968 0472 ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:41:49.0968 0472 ACPI - ok
10:41:50.0031 0472 ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:41:50.0031 0472 ACPIEC - ok
10:41:50.0078 0472 adpu160m        (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:41:50.0078 0472 adpu160m - ok
10:41:50.0140 0472 aec             (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
10:41:50.0156 0472 aec - ok
10:41:50.0218 0472 AegisP          (076394a345ee5e9e3911fc0f058f4f38) C:\WINDOWS\system32\DRIVERS\AegisP.sys
10:41:50.0218 0472 AegisP - ok
10:41:50.0343 0472 AFD             (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
10:41:50.0343 0472 AFD - ok
10:41:50.0421 0472 AFS2K           (0ebb674888cbdefd5773341c16dd6a07) C:\WINDOWS\system32\drivers\AFS2K.sys
10:41:50.0421 0472 AFS2K - ok
10:41:50.0484 0472 agp440          (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:41:50.0484 0472 agp440 - ok
10:41:50.0531 0472 agpCPQ          (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:41:50.0531 0472 agpCPQ - ok
10:41:50.0593 0472 Aha154x         (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:41:50.0593 0472 Aha154x - ok
10:41:50.0656 0472 aic78u2         (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:41:50.0656 0472 aic78u2 - ok
10:41:50.0703 0472 aic78xx         (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:41:50.0703 0472 aic78xx - ok
10:41:50.0750 0472 AliIde          (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
10:41:50.0750 0472 AliIde - ok
10:41:50.0796 0472 alim1541        (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:41:50.0796 0472 alim1541 - ok
10:41:50.0906 0472 amdagp          (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:41:50.0906 0472 amdagp - ok
10:41:50.0953 0472 amsint          (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
10:41:50.0953 0472 amsint - ok
10:41:51.0000 0472 ApfiltrService  (aeb775a2bae0f392ba6adc0bb706233a) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
10:41:51.0015 0472 ApfiltrService - ok
10:41:51.0078 0472 APPDRV          (ec94e05b76d033b74394e7b2175103cf) C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS
10:41:51.0078 0472 APPDRV - ok
10:41:51.0156 0472 Arp1394         (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:41:51.0156 0472 Arp1394 - ok
10:41:51.0218 0472 asc             (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
10:41:51.0218 0472 asc - ok
10:41:51.0281 0472 asc3350p        (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:41:51.0281 0472 asc3350p - ok
10:41:51.0343 0472 asc3550         (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:41:51.0343 0472 asc3550 - ok
10:41:51.0484 0472 Aspi32          (b979979ab8027f7f53fb16ec4229b7db) C:\WINDOWS\system32\drivers\Aspi32.sys
10:41:51.0500 0472 Aspi32 - ok
10:41:51.0562 0472 aswFsBlk        (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys
10:41:51.0578 0472 aswFsBlk - ok
10:41:51.0656 0472 aswMon2         (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys
10:41:51.0656 0472 aswMon2 - ok
10:41:51.0734 0472 aswRdr          (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys
10:41:51.0734 0472 aswRdr - ok
10:41:51.0828 0472 aswSnx          (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys
10:41:51.0843 0472 aswSnx - ok
10:41:51.0937 0472 aswSP           (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys
10:41:51.0968 0472 aswSP - ok
10:41:52.0093 0472 aswTdi          (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys
10:41:52.0093 0472 aswTdi - ok
10:41:52.0171 0472 AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:41:52.0171 0472 AsyncMac - ok
10:41:52.0218 0472 atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:41:52.0218 0472 atapi - ok
10:41:52.0250 0472 Atdisk - ok
10:41:52.0375 0472 ati2mtag        (5b75176663f88e90f14a87e57b8562a4) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
10:41:52.0421 0472 ati2mtag - ok
10:41:52.0484 0472 Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:41:52.0484 0472 Atmarpc - ok
10:41:52.0562 0472 audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:41:52.0562 0472 audstub - ok
10:41:52.0671 0472 bcm4sbxp        (78123f44be9e4768852a3a017e02d637) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
10:41:52.0687 0472 bcm4sbxp - ok
10:41:52.0750 0472 Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:41:52.0765 0472 Beep - ok
10:41:52.0859 0472 BthEnum         (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
10:41:52.0859 0472 BthEnum - ok
10:41:52.0906 0472 BthPan          (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
10:41:52.0921 0472 BthPan - ok
10:41:53.0000 0472 BTHPORT         (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys
10:41:53.0031 0472 BTHPORT - ok
10:41:53.0078 0472 BTHUSB          (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
10:41:53.0078 0472 BTHUSB - ok
10:41:53.0125 0472 bvrp_pci - ok
10:41:53.0218 0472 cbidf           (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:41:53.0218 0472 cbidf - ok
10:41:53.0281 0472 cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:41:53.0281 0472 cbidf2k - ok
10:41:53.0343 0472 CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:41:53.0343 0472 CCDECODE - ok
10:41:53.0406 0472 cd20xrnt        (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:41:53.0406 0472 cd20xrnt - ok
10:41:53.0468 0472 Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:41:53.0468 0472 Cdaudio - ok
10:41:53.0531 0472 Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
10:41:53.0531 0472 Cdfs - ok
10:41:53.0578 0472 Cdrom           (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:41:53.0578 0472 Cdrom - ok
10:41:53.0625 0472 Changer - ok
10:41:53.0687 0472 CmBatt          (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
10:41:53.0687 0472 CmBatt - ok
10:41:53.0796 0472 CmdIde          (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:41:53.0812 0472 CmdIde - ok
10:41:53.0859 0472 Compbatt        (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
10:41:53.0859 0472 Compbatt - ok
10:41:53.0968 0472 Cpqarray        (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:41:53.0968 0472 Cpqarray - ok
10:41:54.0062 0472 dac2w2k         (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:41:54.0062 0472 dac2w2k - ok
10:41:54.0125 0472 dac960nt        (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:41:54.0125 0472 dac960nt - ok
10:41:54.0218 0472 Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
10:41:54.0234 0472 Disk - ok
10:41:54.0328 0472 DLABOIOM        (a14524d3f130a57163e0b3e057fc85d5) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
10:41:54.0328 0472 DLABOIOM - ok
10:41:54.0437 0472 DLACDBHM        (7581407a6a3c56860ae31e6e423fe824) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
10:41:54.0437 0472 DLACDBHM - ok
10:41:54.0500 0472 DLADResN        (7c4cdf8a684b63d7482e0bf7440dc3b5) C:\WINDOWS\system32\DLA\DLADResN.SYS
10:41:54.0500 0472 DLADResN - ok
10:41:54.0546 0472 DLAIFS_M        (97bca2aac06a9fea56615b4b15bdb9b8) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
10:41:54.0562 0472 DLAIFS_M - ok
10:41:54.0609 0472 DLAOPIOM        (be8d558cf749424f0de612813f7c6725) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
10:41:54.0609 0472 DLAOPIOM - ok
10:41:54.0656 0472 DLAPoolM        (7e5277cb45dc5e2a86af8ce093c7ef31) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
10:41:54.0671 0472 DLAPoolM - ok
10:41:54.0734 0472 DLARTL_N        (693dfd92d41a3d270053cd97834e4960) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
10:41:54.0734 0472 DLARTL_N - ok
10:41:54.0843 0472 DLAUDFAM        (d886b6d02b51e5bd61b8a571a16d5ca2) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
10:41:54.0843 0472 DLAUDFAM - ok
10:41:54.0953 0472 DLAUDF_M        (2c0ecf7a9d5162d87c64e2ae868b5039) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
10:41:54.0968 0472 DLAUDF_M - ok
10:41:55.0109 0472 dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
10:41:55.0156 0472 dmboot - ok
10:41:55.0234 0472 dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
10:41:55.0234 0472 dmio - ok
10:41:55.0296 0472 dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:41:55.0296 0472 dmload - ok
10:41:55.0375 0472 DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
10:41:55.0375 0472 DMusic - ok
10:41:55.0484 0472 dpti2o          (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:41:55.0484 0472 dpti2o - ok
10:41:55.0578 0472 drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
10:41:55.0593 0472 drmkaud - ok
10:41:55.0687 0472 drvmcdb         (73623d89faef4d1aa600edee8b490bc5) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
10:41:55.0687 0472 drvmcdb - ok
10:41:55.0734 0472 drvnddm         (2aeee1600d0f14ba535f90a1f4411b54) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
10:41:55.0734 0472 drvnddm - ok
10:41:55.0796 0472 E100B           (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
10:41:55.0796 0472 E100B - ok
10:41:55.0906 0472 Fastfat         (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
10:41:55.0906 0472 Fastfat - ok
10:41:56.0000 0472 Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:41:56.0000 0472 Fdc - ok
10:41:56.0046 0472 Fips            (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
10:41:56.0062 0472 Fips - ok
10:41:56.0109 0472 Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:41:56.0109 0472 Flpydisk - ok
10:41:56.0218 0472 FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
10:41:56.0296 0472 FltMgr - ok
10:41:56.0437 0472 Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:41:56.0453 0472 Fs_Rec - ok
10:41:56.0515 0472 Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:41:56.0531 0472 Ftdisk - ok
10:41:56.0562 0472 GEARAspiWDM     (f2f431d1573ee632975c524418655b84) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
10:41:56.0562 0472 GEARAspiWDM - ok
10:41:56.0609 0472 gmer            (b56eb0a2210980e76390bd670bcb618b) C:\WINDOWS\system32\DRIVERS\gmer.sys
10:41:56.0609 0472 gmer - ok
10:41:56.0640 0472 Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:41:56.0640 0472 Gpc - ok
10:41:56.0671 0472 HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:41:56.0671 0472 HidUsb - ok
10:41:56.0734 0472 hpn             (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
10:41:56.0734 0472 hpn - ok
10:41:56.0796 0472 HPZid412        (5faba4775d4c61e55ec669d643ffc71f) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
10:41:56.0796 0472 HPZid412 - ok
10:41:56.0843 0472 HPZipr12        (a3c43980ee1f1beac778b44ea65dbdd4) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
10:41:56.0859 0472 HPZipr12 - ok
10:41:56.0937 0472 HPZius12        (2906949bd4e206f2bb0dd1896ce9f66f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
10:41:56.0937 0472 HPZius12 - ok
10:41:57.0015 0472 HSFHWICH        (140ba850417896b6b3322048de280368) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
10:41:57.0015 0472 HSFHWICH - ok
10:41:57.0156 0472 HSF_DP          (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
10:41:57.0203 0472 HSF_DP - ok
10:41:57.0296 0472 HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
10:41:57.0312 0472 HTTP - ok
10:41:57.0375 0472 hwdatacard - ok
10:41:57.0453 0472 i2omgmt         (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
10:41:57.0453 0472 i2omgmt - ok
10:41:57.0515 0472 i2omp           (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:41:57.0515 0472 i2omp - ok
10:41:57.0609 0472 i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:41:57.0609 0472 i8042prt - ok
10:41:57.0671 0472 Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:41:57.0671 0472 Imapi - ok
10:41:57.0781 0472 ini910u         (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:41:57.0781 0472 ini910u - ok
10:41:57.0843 0472 IntelIde        (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
10:41:57.0843 0472 IntelIde - ok
10:41:57.0906 0472 intelppm        (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:41:57.0906 0472 intelppm - ok
10:41:57.0984 0472 Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
10:41:57.0984 0472 Ip6Fw - ok
10:41:58.0046 0472 IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:41:58.0046 0472 IpFilterDriver - ok
10:41:58.0140 0472 IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:41:58.0140 0472 IpInIp - ok
10:41:58.0234 0472 IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:41:58.0234 0472 IpNat - ok
10:41:58.0296 0472 IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:41:58.0296 0472 IPSec - ok
10:41:58.0375 0472 IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:41:58.0375 0472 IRENUM - ok
10:41:58.0437 0472 isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:41:58.0437 0472 isapnp - ok
10:41:58.0515 0472 IWCA            (872d090ca5c306f62d1982bce6302376) C:\WINDOWS\system32\DRIVERS\iwca.sys
10:41:58.0515 0472 IWCA - ok
10:41:58.0609 0472 Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:41:58.0609 0472 Kbdclass - ok
10:41:58.0703 0472 kbdhid          (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:41:58.0718 0472 kbdhid - ok
10:41:58.0765 0472 kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
10:41:58.0781 0472 kmixer - ok
10:41:58.0859 0472 KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
10:41:58.0875 0472 KSecDD - ok
10:41:58.0984 0472 Lbd             (419590ebe7855215bb157ea0cf0d0531) C:\WINDOWS\system32\DRIVERS\Lbd.sys
10:41:58.0984 0472 Lbd - ok
10:41:59.0031 0472 lbrtfdc - ok
10:41:59.0109 0472 Lvckap - ok
10:41:59.0187 0472 LVPr2Mon        (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
10:41:59.0187 0472 LVPr2Mon - ok
10:41:59.0265 0472 mdmxsdk         (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
10:41:59.0265 0472 mdmxsdk - ok
10:41:59.0343 0472 mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:41:59.0343 0472 mnmdd - ok
10:41:59.0421 0472 Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
10:41:59.0437 0472 Modem - ok
10:41:59.0531 0472 Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:41:59.0531 0472 Mouclass - ok
10:41:59.0593 0472 mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:41:59.0593 0472 mouhid - ok
10:41:59.0671 0472 MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
10:41:59.0671 0472 MountMgr - ok
10:41:59.0718 0472 mraid35x        (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:41:59.0734 0472 mraid35x - ok
10:41:59.0812 0472 MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:41:59.0812 0472 MRxDAV - ok
10:41:59.0921 0472 MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:41:59.0937 0472 MRxSmb - ok
10:42:00.0062 0472 Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
10:42:00.0078 0472 Msfs - ok
10:42:00.0140 0472 MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:42:00.0140 0472 MSKSSRV - ok
10:42:00.0203 0472 MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:42:00.0218 0472 MSPCLOCK - ok
10:42:00.0281 0472 MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
10:42:00.0281 0472 MSPQM - ok
10:42:00.0359 0472 mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:42:00.0375 0472 mssmbios - ok
10:42:00.0437 0472 MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
10:42:00.0437 0472 MSTEE - ok
10:42:00.0531 0472 Mup             (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
10:42:00.0531 0472 Mup - ok
10:42:00.0625 0472 NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:42:00.0640 0472 NABTSFEC - ok
10:42:00.0734 0472 NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
10:42:00.0734 0472 NDIS - ok
10:42:00.0796 0472 NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:42:00.0812 0472 NdisIP - ok
10:42:00.0906 0472 NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:42:00.0921 0472 NdisTapi - ok
10:42:00.0984 0472 Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:42:00.0984 0472 Ndisuio - ok
10:42:01.0046 0472 NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:42:01.0046 0472 NdisWan - ok
10:42:01.0171 0472 NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
10:42:01.0171 0472 NDProxy - ok
10:42:01.0250 0472 NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
10:42:01.0250 0472 NetBIOS - ok
10:42:01.0312 0472 NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:42:01.0328 0472 NetBT - ok
10:42:01.0765 0472 NIC1394         (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:42:01.0765 0472 NIC1394 - ok
10:42:01.0812 0472 Nokia USB Generic (1926b4eef80f4a0c8cc8fcbb6b4a7461) C:\WINDOWS\system32\drivers\nmwcdc.sys
10:42:01.0812 0472 Nokia USB Generic - ok
10:42:01.0875 0472 Nokia USB Modem (df4211b6ca609ff11f43261e04ac92f1) C:\WINDOWS\system32\drivers\nmwcdcm.sys
10:42:01.0875 0472 Nokia USB Modem - ok
10:42:01.0921 0472 Nokia USB Phone Parent (ddfe78eeb4afcf91edc52b8f7c7dad15) C:\WINDOWS\system32\drivers\nmwcd.sys
10:42:01.0921 0472 Nokia USB Phone Parent - ok
10:42:02.0000 0472 Nokia USB Port  (df4211b6ca609ff11f43261e04ac92f1) C:\WINDOWS\system32\drivers\nmwcdcj.sys
10:42:02.0000 0472 Nokia USB Port - ok
10:42:02.0062 0472 Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
10:42:02.0062 0472 Npfs - ok
10:42:02.0171 0472 Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
10:42:02.0187 0472 Ntfs - ok
10:42:02.0250 0472 Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:42:02.0265 0472 Null - ok
10:42:02.0421 0472 nv              (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:42:02.0515 0472 nv - ok
10:42:02.0562 0472 NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:42:02.0578 0472 NwlnkFlt - ok
10:42:02.0656 0472 NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:42:02.0656 0472 NwlnkFwd - ok
10:42:02.0734 0472 NwlnkIpx        (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
10:42:02.0750 0472 NwlnkIpx - ok
10:42:02.0812 0472 NwlnkNb         (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
10:42:02.0812 0472 NwlnkNb - ok
10:42:02.0875 0472 NwlnkSpx        (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
10:42:02.0875 0472 NwlnkSpx - ok
10:42:02.0953 0472 ohci1394        (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:42:02.0953 0472 ohci1394 - ok
10:42:03.0046 0472 omci            (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys
10:42:03.0062 0472 omci - ok
10:42:03.0125 0472 Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
10:42:03.0140 0472 Parport - ok
10:42:03.0218 0472 PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
10:42:03.0234 0472 PartMgr - ok
10:42:03.0328 0472 ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
10:42:03.0328 0472 ParVdm - ok
10:42:03.0375 0472 PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
10:42:03.0390 0472 PCI - ok
10:42:03.0437 0472 PCIDump - ok
10:42:03.0515 0472 PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:42:03.0515 0472 PCIIde - ok
10:42:03.0593 0472 Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
10:42:03.0593 0472 Pcmcia - ok
10:42:03.0656 0472 PDCOMP - ok
10:42:03.0703 0472 PDFRAME - ok
10:42:03.0781 0472 PDRELI - ok
10:42:03.0843 0472 PDRFRAME - ok
10:42:03.0921 0472 perc2           (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
10:42:03.0921 0472 perc2 - ok
10:42:03.0984 0472 perc2hib        (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:42:03.0984 0472 perc2hib - ok
10:42:04.0125 0472 PID_0928        (d2d2fa02b722336960eeae0ae7107891) C:\WINDOWS\system32\DRIVERS\LV561AV.SYS
10:42:04.0156 0472 PID_0928 - ok
10:42:04.0281 0472 PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:42:04.0296 0472 PptpMiniport - ok
10:42:04.0375 0472 PQNTDrv         (4228630829c0e521c43d882a00533374) C:\WINDOWS\system32\drivers\PQNTDrv.sys
10:42:04.0375 0472 PQNTDrv - ok
10:42:04.0437 0472 PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
10:42:04.0437 0472 PSched - ok
10:42:04.0515 0472 Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:42:04.0515 0472 Ptilink - ok
10:42:04.0593 0472 PxHelp20        (49452bfcec22f36a7a9b9c2181bc3042) C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:42:04.0609 0472 PxHelp20 - ok
10:42:04.0703 0472 ql1080          (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:42:04.0703 0472 ql1080 - ok
10:42:04.0765 0472 Ql10wnt         (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:42:04.0765 0472 Ql10wnt - ok
10:42:04.0812 0472 ql12160         (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:42:04.0828 0472 ql12160 - ok
10:42:04.0890 0472 ql1240          (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:42:04.0890 0472 ql1240 - ok
10:42:04.0937 0472 ql1280          (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:42:04.0953 0472 ql1280 - ok
10:42:05.0015 0472 RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:42:05.0062 0472 RasAcd - ok
10:42:05.0125 0472 Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:42:05.0125 0472 Rasl2tp - ok
10:42:05.0218 0472 RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:42:05.0218 0472 RasPppoe - ok
10:42:05.0281 0472 Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:42:05.0281 0472 Raspti - ok
10:42:05.0359 0472 Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:42:05.0359 0472 Rdbss - ok
10:42:05.0421 0472 RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:42:05.0437 0472 RDPCDD - ok
10:42:05.0500 0472 rdpdr           (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:42:05.0515 0472 rdpdr - ok
10:42:05.0656 0472 RDPWD           (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
10:42:05.0671 0472 RDPWD - ok
10:42:05.0781 0472 redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:42:05.0781 0472 redbook - ok
10:42:05.0859 0472 RFCOMM          (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
10:42:05.0859 0472 RFCOMM - ok
10:42:05.0968 0472 s24trans        (81aa6f0d6a2be1c550f814b036215888) C:\WINDOWS\system32\DRIVERS\s24trans.sys
10:42:05.0968 0472 s24trans - ok
10:42:06.0078 0472 sdbus           (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
10:42:06.0093 0472 sdbus - ok
10:42:06.0203 0472 Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:42:06.0203 0472 Secdrv - ok
10:42:06.0281 0472 serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:42:06.0281 0472 serenum - ok
10:42:06.0375 0472 Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
10:42:06.0390 0472 Serial - ok
10:42:06.0500 0472 sffdisk         (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
10:42:06.0500 0472 sffdisk - ok
10:42:06.0546 0472 sffp_sd         (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
10:42:06.0562 0472 sffp_sd - ok
10:42:06.0625 0472 Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:42:06.0625 0472 Sfloppy - ok
10:42:06.0703 0472 Simbad - ok
10:42:06.0781 0472 sisagp          (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:42:06.0796 0472 sisagp - ok
10:42:06.0875 0472 SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:42:06.0890 0472 SLIP - ok
10:42:06.0968 0472 Sparrow         (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:42:06.0984 0472 Sparrow - ok
10:42:07.0062 0472 splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
10:42:07.0062 0472 splitter - ok
10:42:07.0171 0472 sptd            (4f576e516cc76ec50a244586bcfa1c78) C:\WINDOWS\system32\Drivers\sptd.sys
10:42:07.0171 0472 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 4f576e516cc76ec50a244586bcfa1c78
10:42:07.0187 0472 sptd ( LockedFile.Multi.Generic ) - warning
10:42:07.0187 0472 sptd - detected LockedFile.Multi.Generic (1)
10:42:07.0281 0472 sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
10:42:07.0281 0472 sr - ok
10:42:07.0406 0472 Srv             (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
10:42:07.0437 0472 Srv - ok
10:42:07.0531 0472 ssm_bus         (e528a2ffa9319ab13be5f7f2069144ef) C:\WINDOWS\system32\DRIVERS\ssm_bus.sys
10:42:07.0546 0472 ssm_bus - ok
10:42:07.0625 0472 ssm_mdfl        (f778289ca4eb8db3cd24b3a52e7cf90d) C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys
10:42:07.0625 0472 ssm_mdfl - ok
10:42:07.0687 0472 ssm_mdm         (04b81b54a2ed2ce23695f306720031cf) C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys
10:42:07.0703 0472 ssm_mdm - ok
10:42:07.0781 0472 STAC97          (25068674e358fd74bfa612f175c6721b) C:\WINDOWS\system32\drivers\STAC97.sys
10:42:07.0796 0472 STAC97 - ok
10:42:07.0890 0472 streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:42:07.0890 0472 streamip - ok
10:42:07.0984 0472 STV672          (52adfd8d850145e3c56d7505e29d34ca) C:\WINDOWS\system32\drivers\STV672.sys
10:42:07.0984 0472 STV672 - ok
10:42:08.0046 0472 swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:42:08.0062 0472 swenum - ok
10:42:08.0125 0472 swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
10:42:08.0140 0472 swmidi - ok
10:42:08.0218 0472 symc810         (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
10:42:08.0218 0472 symc810 - ok
10:42:08.0296 0472 symc8xx         (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:42:08.0312 0472 symc8xx - ok
10:42:08.0375 0472 sym_hi          (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:42:08.0390 0472 sym_hi - ok
10:42:08.0453 0472 sym_u3          (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:42:08.0468 0472 sym_u3 - ok
10:42:08.0562 0472 sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
10:42:08.0578 0472 sysaudio - ok
10:42:08.0671 0472 tapvpn          (27a2c318cd28cfb3eb2200fd96af1e58) C:\WINDOWS\system32\DRIVERS\tapvpn.sys
10:42:08.0671 0472 tapvpn - ok
10:42:08.0750 0472 Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:42:08.0781 0472 Tcpip - ok
10:42:08.0859 0472 TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:42:08.0859 0472 TDPIPE - ok
10:42:08.0921 0472 TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
10:42:08.0921 0472 TDTCP - ok
10:42:09.0000 0472 TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:42:09.0000 0472 TermDD - ok
10:42:09.0125 0472 tmcomm          (df8444a8fa8fd38d8848bdd40a8403b3) C:\WINDOWS\system32\drivers\tmcomm.sys
10:42:09.0140 0472 tmcomm - ok
10:42:09.0218 0472 TosIde          (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
10:42:09.0218 0472 TosIde - ok
10:42:09.0312 0472 Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
10:42:09.0312 0472 Udfs - ok
10:42:09.0390 0472 ultra           (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
10:42:09.0390 0472 ultra - ok
10:42:09.0468 0472 Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
10:42:09.0484 0472 Update - ok
10:42:09.0593 0472 USBAAPL         (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys
10:42:09.0593 0472 USBAAPL - ok
10:42:09.0671 0472 usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:42:09.0671 0472 usbccgp - ok
10:42:09.0750 0472 usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:42:09.0750 0472 usbehci - ok
10:42:09.0828 0472 usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:42:09.0828 0472 usbhub - ok
10:42:09.0906 0472 usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:42:09.0921 0472 usbprint - ok
10:42:10.0000 0472 usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:42:10.0000 0472 usbscan - ok
10:42:10.0062 0472 USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:42:10.0062 0472 USBSTOR - ok
10:42:10.0156 0472 usbuhci         (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:42:10.0156 0472 usbuhci - ok
10:42:10.0218 0472 usb_rndisx      (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
10:42:10.0234 0472 usb_rndisx - ok
10:42:10.0296 0472 VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
10:42:10.0312 0472 VgaSave - ok
10:42:10.0375 0472 viaagp          (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:42:10.0375 0472 viaagp - ok
10:42:10.0453 0472 ViaIde          (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
10:42:10.0468 0472 ViaIde - ok
10:42:10.0531 0472 VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
10:42:10.0546 0472 VolSnap - ok
10:42:10.0750 0472 w29n51          (f0f902220910c4fbe42a51964bd33599) C:\WINDOWS\system32\DRIVERS\w29n51.sys
10:42:10.0906 0472 w29n51 - ok
10:42:11.0000 0472 Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:42:11.0000 0472 Wanarp - ok
10:42:11.0109 0472 Wdf01000        (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
10:42:11.0140 0472 Wdf01000 - ok
10:42:11.0203 0472 WDICA - ok
10:42:11.0281 0472 wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
10:42:11.0281 0472 wdmaud - ok
10:42:11.0421 0472 winachsf        (2dc7c0b6175a0a8ed84a4f70199c93b5) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
10:42:11.0453 0472 winachsf - ok
10:42:11.0640 0472 WpdUsb          (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:42:11.0640 0472 WpdUsb - ok
10:42:11.0718 0472 WS2IFSL         (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
10:42:11.0718 0472 WS2IFSL - ok
10:42:11.0796 0472 WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:42:11.0812 0472 WSTCODEC - ok
10:42:11.0890 0472 WudfPf          (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:42:11.0890 0472 WudfPf - ok
10:42:11.0953 0472 WudfRd          (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:42:11.0968 0472 WudfRd - ok
10:42:12.0078 0472 MBR (0x1B8)     (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
10:42:12.0312 0472 \Device\Harddisk0\DR0 - ok
10:42:12.0328 0472 Boot (0x1200)   (f94b36580f5b9c3999df4aaa4b80c4a7) \Device\Harddisk0\DR0\Partition0
10:42:12.0328 0472 \Device\Harddisk0\DR0\Partition0 - ok
10:42:12.0359 0472 Boot (0x1200)   (53dcce98b8f68d3409dbcee1c632f0af) \Device\Harddisk0\DR0\Partition1
10:42:12.0375 0472 \Device\Harddisk0\DR0\Partition1 - ok
10:42:12.0375 0472 ============================================================
10:42:12.0375 0472 Scan finished
10:42:12.0375 0472 ============================================================
10:42:12.0390 2864 Detected object count: 1
10:42:12.0390 2864 Actual detected object count: 1
10:46:42.0515 2864 sptd ( LockedFile.Multi.Generic ) - skipped by user
10:46:42.0515 2864 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
10:46:51.0250 2216 Deinitialize success








ComboFix 12-02-03.02 - Basti 04/02/2012  10:53:15.4.1 - x86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1023.601 [GMT 11:00]
Running from: c:\documents and settings\Basti\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Basti\My Documents\DPE.DUS
c:\documents and settings\Basti\WINDOWS
c:\program files\Dell\Media Experience\DMXLauncher.exe
c:\windows\Downloaded Installations\BMP
c:\windows\Downloaded Installations\BMP\{A9A9EAFE-569D-4F22-8013-ADDCCEF13A7E}\0x0409.ini
c:\windows\Downloaded Installations\BMP\{A9A9EAFE-569D-4F22-8013-ADDCCEF13A7E}\1033.MST
c:\windows\Downloaded Installations\BMP\{A9A9EAFE-569D-4F22-8013-ADDCCEF13A7E}\BACS.msi
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_VCS
.
.
(((((((((((((((((((((((((   Files Created from 2012-01-04 to 2012-02-04  )))))))))))))))))))))))))))))))
.
.
2012-02-03 12:55 . 2012-02-03 12:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-03 12:55 . 2011-12-10 04:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-03 12:21 . 2012-02-03 12:21 -------- d-----w- C:\_OTL
2012-02-03 12:06 . 2012-02-03 12:06 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-03 11:56 . 2012-02-03 11:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 11:49 . 2012-02-03 11:49 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-02-03 11:45 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-01-31 05:39 . 2012-01-31 05:39 388096 ----a-r- c:\documents and settings\Basti\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-17 14:00 . 2011-12-08 05:07 892928 ----a-w- c:\windows\system32\iconv.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-03 12:06 . 2010-08-25 08:10 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-26 13:21 . 2009-10-07 11:06 237072 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2010-09-28 23:04 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2008-07-03 08:47 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2008-07-03 08:48 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2009-01-25 12:15 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2009-01-25 12:15 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2009-01-25 12:15 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2008-07-03 08:48 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2008-07-03 08:48 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2009-01-25 12:15 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2004-08-03 21:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2004-08-03 21:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2004-08-03 21:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-08-03 21:00 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2004-08-03 21:00 152064 ----a-w- c:\windows\system32\schannel.dll
2006-05-03 09:06 163328 --sh--r- c:\windows\SYSTEM32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\SYSTEM32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\SYSTEM32\nbDX.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Timezone"="c:\program files\Microsoft Time Zone\TimeZone.exe" [2004-10-19 712704]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-04-22 1196032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-12 127036]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2011-07-25 528832]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2005-02-07 606208]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-26 59240]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-01 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AutoLaunch"="c:\program files\Lavasoft\Ad-Aware\AutoLaunch.exe" [2011-07-25 669936]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-4-25 24576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 08:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GetRight - Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GetRight - Tray Icon.lnk
backup=c:\windows\pss\GetRight - Tray Icon.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\palstart.exe
backup=c:\windows\pss\palstart.exeCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalStart.lnk
backup=c:\windows\pss\PalStart.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ultra Hal Text-to-Speech Reader Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Ultra Hal Text-to-Speech Reader Startup.lnk
backup=c:\windows\pss\Ultra Hal Text-to-Speech Reader Startup.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Unwired Launchpad.lnk
backup=c:\windows\pss\Unwired Launchpad.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Basti^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Basti\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Basti^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Basti\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Basti^Start Menu^Programs^Startup^Unwired Launchpad.lnk]
path=c:\documents and settings\Basti\Start Menu\Programs\Startup\Unwired Launchpad.lnk
backup=c:\windows\pss\Unwired Launchpad.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2004-09-13 03:33 155648 -c--a-w- c:\program files\Apoint\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2007-04-03 22:29 165784 ----a-w- d:\daemon tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 08:54 57344 -c----w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2004-05-12 04:18 241664 ----a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-02-12 02:38 49152 -c--a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 00:35 2780432 -c--a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-05-31 23:17 5252408 ----a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 11:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 07:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-09-29 07:15 214448 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2006-09-29 07:15 185784 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2004-01-06 17:01 110592 -c--a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MskService"=2 (0x2)
"mcupdmgr.exe"=2 (0x2)
"McTskshd.exe"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Senstic\\i-Clickr\\i-Clickr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\temp\\janinblr\\iTunnel\\iTunnel.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Basti\\My Documents\\Downloads\\tinyumbrella-5.00.00.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [21/01/2009 11:25 PM 64160]
R0 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [25/06/2007 8:40 PM 682232]
R1 aswSnx;aswSnx;c:\windows\SYSTEM32\DRIVERS\aswSnx.sys [3/02/2012 10:45 PM 435032]
R1 aswSP;aswSP;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [3/07/2008 7:48 PM 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [3/07/2008 7:48 PM 20568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 8:34 AM 1036104]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 13:26]
.
2011-07-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 01:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\documents and settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Cooliris: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Sothink Web Video Downloader for Firefox: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08} - %profile%\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DMXLauncher - c:\program files\Dell\Media Experience\DMXLauncher.exe
MSConfigStartUp-eBayToolbar - c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-Logitech Vid - c:\program files\Logitech\Logitech Vid\vid.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\McAgent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\mcupdate.exe
MSConfigStartUp-PCSuiteTrayApplication - c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
AddRemove-CinemaForge - c:\windows\system32\xmirage.exe d\CinemaForge\UninstallCF.xmfg
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-04 11:14
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entr

15
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 03, 2012, 08:45:32 AM »
Hi guestolo

I followed all your instructions, there was a little hick u with malwarebytes when i tried to update but i just uninstalled my version and installed a new one. I also downlaoded all the latst updates.

Please find below the latest to loggs as requested. Unfortuanetly Firefox still does not open -((

Your continues help is like always much appreciated!!!!


All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1699012c-2a90-11df-aabf-001f81000250}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1699012c-2a90-11df-aabf-001f81000250}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1699012c-2a90-11df-aabf-001f81000250}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6149c55d-f7e9-11dc-a658-00114374ee38}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6149c55d-f7e9-11dc-a658-00114374ee38}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6149c55d-f7e9-11dc-a658-00114374ee38}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6cdec37a-a26d-11dd-a7fb-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6cdec37a-a26d-11dd-a7fb-0012f04276e6}\ not found.
File G:\setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77254c42-a94d-11dc-a588-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77254c42-a94d-11dc-a588-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77254c42-a94d-11dc-a588-0012f04276e6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486a-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486a-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486a-a94b-11dc-a587-0012f04276e6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486b-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486b-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486b-a94b-11dc-a587-0012f04276e6}\ not found.
File G:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486c-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486c-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a133486c-a94b-11dc-a587-0012f04276e6}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c6df0e2e-5290-11de-a95c-0012f04276e6}\ not found.
File H:\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\ not found.
File G:\NetTV-Stick.exe not found.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
ADS C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\TkBellExe deleted successfully.
========== FILES ==========
File\Folder C:\WINDOWS\tasks\MP Scheduled Scan.job not found.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Basti\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Basti\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYFLASH]
 
User: Administrator
 
User: All Users
 
User: Basti
->Flash cache emptied: 1573381 bytes
 
User: Default User
->Flash cache emptied: 56475 bytes
 
User: LocalService
->Flash cache emptied: 300 bytes
 
User: NetworkService
 
Total Flash Files Cleaned = 2.00 mb
 
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: All Users
 
User: Basti
->Temp folder emptied: 61034886 bytes
->Temporary Internet Files folder emptied: 35221737 bytes
->Java cache emptied: 43832835 bytes
->FireFox cache emptied: 49533040 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes
 
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 23393771 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 171582492 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 367.00 mb
 
 
OTL by OldTimer - Version 3.2.31.0 log created on 02032012_232138

Files\Folders moved on Reboot...
C:\Documents and Settings\Basti\Local Settings\Temp\WCESLog.log moved successfully.
C:\Documents and Settings\Basti\Local Settings\Temporary Internet Files\Content.IE5\YTUPDS4C\ads[2].htm moved successfully.
C:\Documents and Settings\Basti\Local Settings\Temporary Internet Files\Content.IE5\YTUPDS4C\index[1].htm moved successfully.
C:\Documents and Settings\Basti\Local Settings\Temporary Internet Files\Content.IE5\UVTYD93A\ads[4].htm moved successfully.
File move failed. C:\WINDOWS\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...












Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.03.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Basti :: D1JD5F1S [administrator]

3/02/2012 11:57:57 PM
mbam-log-2012-02-03 (23-57-57).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 196758
Time elapsed: 12 minute(s), 19 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\System\CurrentControlSet\Services\gaopdxserv.sys (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)



16
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: February 02, 2012, 03:09:25 AM »
Hi,

I have disabled ad-aware and removed McAfee using the MCPR.exe file.

Here is the lates log as requested, thanks again for your help:


OTL logfile created on: 2/02/2012 7:01:53 PM - Run 2
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 440.64 Mb Available Physical Memory | 43.06% Memory free
2.40 Gb Paging File | 1.85 Gb Available in Paging File | 76.98% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 3.47 Gb Free Space | 10.13% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 3.00 Gb Free Space | 7.46% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
PRC - [2011/07/26 00:26:20 | 000,528,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/05/26 07:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2010/09/08 02:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/09/29 18:15:36 | 000,185,784 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2006/06/13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE
PRC - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/10/30 17:59:54 | 000,385,024 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2004/09/15 04:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004/09/07 19:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004/09/07 19:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/02/02 09:57:50 | 001,697,280 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12020101\algo.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 00:27:03 | 000,090,592 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll
MOD - [2011/07/26 00:27:01 | 001,640,216 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\Resources.dll
MOD - [2011/07/26 00:26:57 | 000,256,424 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
MOD - [2010/09/08 02:13:40 | 000,142,872 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\aswDld.dll
MOD - [2008/09/11 09:00:05 | 000,168,960 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\unrar.dll
MOD - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
MOD - [2008/01/23 10:45:18 | 000,310,616 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libssl32.dll
MOD - [2008/01/23 10:45:16 | 001,527,751 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libeay32.dll
MOD - [2007/05/22 11:59:22 | 000,128,512 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2005/04/22 19:17:18 | 000,010,752 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/12/23 18:47:36 | 000,069,632 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2004/09/15 04:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
MOD - [2004/09/07 19:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
MOD - [2003/07/30 00:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
SRV - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2006/11/06 15:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\HPZipm12.exe -- (Pml Driver HPZ12)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010/09/08 01:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/08 01:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/08 01:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/08 01:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/08 01:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/08 01:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/05/12 00:38:32 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/01/28 11:04:00 | 000,085,969 | ---- | M] (GMER) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\gmer.sys -- (gmer)
DRV - [2008/04/14 05:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/24 08:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tapvpn.sys -- (tapvpn)
DRV - [2007/08/13 11:29:08 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - [2007/08/01 23:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/06/25 20:40:19 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/10/10 09:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006/10/10 09:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006/10/10 09:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006/10/10 09:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2004/12/04 00:34:26 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/16 13:03:52 | 000,108,791 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/21 18:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys -- (w29n51) Intel(R)
DRV - [2004/10/08 12:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/21 11:55:20 | 000,084,512 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdm.sys -- (ssm_mdm)
DRV - [2004/09/21 11:55:20 | 000,006,096 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2004/09/21 11:55:18 | 000,052,416 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_bus.sys -- (ssm_bus) Samsung Mobile USB Device II 1.0 driver (WDM)
DRV - [2004/09/15 22:53:12 | 000,271,704 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys -- (STAC97)
DRV - [2004/08/31 11:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2004/08/18 17:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/12 11:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys -- (IWCA)
DRV - [2004/08/04 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/08/04 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/06/17 18:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 18:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 18:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2004/05/26 18:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/02/13 13:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/09/16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001/07/03 16:47:02 | 000,103,792 | ---- | M] (STMicroelectronics                                          ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\STV672.sys -- (STV672)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\@xmlauthor.com/downloads: C:\WINDOWS\system32\npmirage.dll (XMLAuthor Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Basti\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/28 21:48:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/26 10:56:22 | 000,000,000 | ---D | M]
 
[2009/01/17 18:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Extensions
[2011/06/28 11:53:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions
[2010/09/29 10:00:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/21 15:10:25 | 000,000,000 | ---D | M] (Sothink Web Video Downloader for Firefox) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2010/09/29 10:00:01 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2010/09/29 10:00:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2011/06/28 11:53:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/25 19:10:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/12/20 21:30:07 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/07/25 20:47:23 | 000,000,000 | ---D | M] (Orbit Downloader Firefox Integration) -- C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ORBITFF
[2010/07/17 06:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2011/06/16 20:20:36 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/06/16 20:20:36 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/06/16 20:20:36 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/06/16 20:20:36 | 000,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2011/10/13 18:17:43 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (PaltalkWebLogin) - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll (AVM Software Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\DLASHX_W.DLL (Sonic Solutions)
O3 - HKLM\..\Toolbar: (no name) -  - No CLSID value found.
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Timezone] C:\Program Files\Microsoft Time Zone\TimeZone.exe (Microsoft)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://D:\FlashCapture\fciext.dll/FCIEXT.htm File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www4.snapfish.com.au/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{224F3BDC-E16C-483D-9088-91290CED9ABA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 16:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/10/17 19:38:57 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007/09/28 19:42:02 | 000,002,292 | ---- | M] () - C:\autorun.PNF -- [ NTFS ]
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell - "" = AutoRun
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell - "" = AutoRun
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6cdec37a-a26d-11dd-a7fb-0012f04276e6}\Shell\AutoRun\command - "" = G:\setupSNK.exe
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell\AutoRun\command - "" = G:\NetTV-Stick.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/01/31 18:51:07 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Start Menu\Programs\HiJackThis
[2012/01/22 22:18:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Any Video Converter
[2012/01/22 21:59:27 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/01/18 01:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Aimersoft DVD Ripper
[2012/01/18 01:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Aimersoft
[2012/01/18 01:00:23 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\WINDOWS\System32\iconv.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/02/02 19:04:50 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/02/02 18:47:04 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2012/02/02 18:45:10 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2012/02/02 18:43:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2012/02/02 18:43:40 | 1073,152,000 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 17:39:17 | 000,015,232 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/22 22:28:48 | 000,099,328 | ---- | M] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/22 21:59:27 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/01/18 01:31:22 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/18 01:01:44 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/17 18:57:36 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/17 18:32:44 | 000,446,424 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2012/01/17 18:32:44 | 000,073,464 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2012/01/17 17:47:25 | 000,831,743 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:06 | 022,328,992 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/01/31 17:39:17 | 000,015,232 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/17 17:47:24 | 000,831,743 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:04 | 022,328,992 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[2010/08/26 02:05:48 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\winscp.rnd
[2010/08/07 18:05:27 | 000,073,684 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/06/05 20:50:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/28 16:16:24 | 000,104,182 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2009/11/28 16:16:24 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2009/05/08 11:13:04 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 23:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/04/30 17:00:12 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/02/22 15:45:42 | 000,641,021 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2009/02/22 15:45:42 | 000,187,904 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2009/02/22 15:45:42 | 000,166,912 | ---- | C] () -- C:\WINDOWS\System32\Lame_enc.dll
[2009/02/22 15:45:42 | 000,002,890 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/01/31 18:51:04 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/28 11:04:01 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/28 11:04:00 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/28 11:03:59 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/27 19:01:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/27 19:01:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/27 19:01:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/27 19:01:25 | 000,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/22 07:09:03 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/01/17 18:30:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/10/01 22:41:06 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/10/01 22:41:06 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/10/01 22:41:06 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/10/01 22:41:06 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/10/01 18:36:23 | 000,000,074 | -H-- | C] () -- C:\WINDOWS\uce.dat
[2008/07/03 01:43:26 | 000,013,805 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/03 01:42:59 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/04/30 23:28:31 | 000,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008/04/30 23:28:31 | 000,066,560 | ---- | C] () -- C:\WINDOWS\MOTA113.exe
[2008/04/30 23:28:31 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008/04/30 23:28:30 | 000,502,784 | ---- | C] () -- C:\WINDOWS\x2.64.exe
[2008/04/30 23:28:30 | 000,240,128 | ---- | C] () -- C:\WINDOWS\System32\x.264.exe
[2008/04/30 23:28:30 | 000,217,073 | ---- | C] () -- C:\WINDOWS\meta4.exe
[2008/01/04 08:11:11 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/13 14:40:54 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2007/02/22 11:13:50 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/29 18:18:33 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/02/27 22:22:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CompanionApp.INI
[2006/02/27 22:19:44 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\$_hpcst$.hpc
[2006/01/28 12:31:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/10/26 17:03:16 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/10/26 16:59:36 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/08/22 11:16:29 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\p.dat
[2005/08/22 11:15:48 | 000,129,822 | ---- | C] () -- C:\WINDOWS\System32\system.dat
[2005/06/18 18:13:39 | 000,099,328 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/05/25 08:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005/05/06 12:36:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\fusioncache.dat
[2005/05/06 12:17:14 | 000,000,300 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/05/06 12:16:49 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2005/05/06 12:16:44 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2005/05/06 11:51:35 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\instlsp.exe
[2005/05/05 20:52:49 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/04/28 15:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/28 15:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/28 15:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/04/25 17:05:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/04/25 17:03:17 | 000,000,344 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/04/25 16:59:24 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/04/25 16:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2005/04/25 16:45:06 | 000,446,424 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2005/04/25 16:45:06 | 000,073,464 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2005/04/25 16:36:32 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/12/20 11:08:28 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/10/15 21:56:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/12 11:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2004/08/10 16:13:12 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 16:08:08 | 000,341,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 16:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 16:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 13:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 19:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1999/07/23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1996/02/24 08:34:48 | 000,014,629 | ---- | C] () -- C:\WINDOWS\System32\Declw.dll
[1996/02/23 06:09:20 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\Decln.dll
[1980/01/01 03:00:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F

< End of report >



17
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: January 31, 2012, 03:03:01 AM »
Hi guestolo

Thanks for your reply. Please find requested logs below:

OTL.TXT
OTL logfile created on: 31/01/2012 6:52:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 596.16 Mb Available Physical Memory | 58.25% Memory free
2.40 Gb Paging File | 2.00 Gb Available in Paging File | 83.16% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 3.70 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 3.00 Gb Free Space | 7.46% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
PRC - [2010/11/29 19:19:36 | 001,234,224 | ---- | M] (Apple Inc.) -- C:\Program Files\QuickTime\QuickTimePlayer.exe
PRC - [2010/09/08 02:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2008/04/14 11:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/09/29 18:15:36 | 000,185,784 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2006/06/13 06:20:00 | 000,127,036 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE
PRC - [2005/07/06 21:06:36 | 000,126,976 | ---- | M] (McAfee, Inc) -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe
PRC - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2004/10/30 17:59:54 | 000,385,024 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
PRC - [2004/09/15 04:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
PRC - [2004/09/07 19:08:02 | 000,389,120 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
PRC - [2004/09/07 19:03:40 | 000,245,760 | ---- | M] (Intel) -- C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/01/31 06:36:54 | 001,688,064 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\12013001\algo.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/26 00:27:03 | 000,090,592 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll
MOD - [2010/09/08 02:13:40 | 000,142,872 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\aswDld.dll
MOD - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
MOD - [2008/01/23 10:45:18 | 000,310,616 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libssl32.dll
MOD - [2008/01/23 10:45:16 | 001,527,751 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\libeay32.dll
MOD - [2007/05/22 11:59:22 | 000,128,512 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2005/04/22 19:17:18 | 000,010,752 | ---- | M] () -- C:\Program Files\Microsoft ActiveSync\rapiproxystub.dll
MOD - [2005/02/07 11:43:08 | 000,606,208 | ---- | M] () -- C:\Program Files\Dell\QuickSet\quickset.exe
MOD - [2004/12/23 18:47:36 | 000,069,632 | ---- | M] () -- C:\Program Files\Dell\QuickSet\dadkeyb.dll
MOD - [2004/09/15 04:01:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
MOD - [2004/09/07 19:03:46 | 000,073,728 | ---- | M] () -- C:\Program Files\Intel\Wireless\Bin\D8021Xps.DLL
MOD - [2003/07/30 00:27:40 | 000,078,336 | ---- | M] () -- C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] --  -- (AppMgmt)
SRV - [2011/07/26 00:26:17 | 001,036,104 | ---- | M] (Lavasoft) [Auto | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/08 02:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2009/04/30 17:01:10 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/06/28 11:34:46 | 000,084,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
SRV - [2006/11/06 15:21:10 | 000,210,432 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006/11/03 19:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005/07/12 13:43:04 | 000,121,344 | ---- | M] (McAfee, Inc) [Disabled | Stopped] -- c:\Program Files\McAfee.com\Agent\McTskshd.exe -- (McTskshd.exe)
SRV - [2005/07/06 21:06:36 | 000,126,976 | ---- | M] (McAfee, Inc) [Auto | Running] -- c:\Program Files\McAfee.com\Agent\Mcdetect.exe -- (McDetect.exe)
SRV - [2005/07/01 20:22:50 | 000,245,760 | ---- | M] (McAfee, Inc) [Disabled | Stopped] -- C:\Program Files\McAfee.com\Agent\mcupdmgr.exe -- (mcupdmgr.exe)
SRV - [2004/09/07 19:12:32 | 000,225,353 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe -- (WLANKEEPER)
SRV - [2004/03/18 16:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\HPZipm12.exe -- (Pml Driver HPZ12)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010/09/08 01:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/08 01:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/08 01:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/08 01:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/08 01:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/08 01:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/05/12 00:38:32 | 000,064,160 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009/04/30 22:56:32 | 000,495,768 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2009/04/30 17:00:12 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/01/28 11:04:00 | 000,085,969 | ---- | M] (GMER) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\gmer.sys -- (gmer)
DRV - [2008/04/14 05:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/01/24 08:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tapvpn.sys -- (tapvpn)
DRV - [2007/08/13 11:29:08 | 000,101,120 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - [2007/08/01 23:47:26 | 000,102,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys -- (tmcomm)
DRV - [2007/06/25 20:40:19 | 000,682,232 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2006/10/10 09:54:34 | 000,138,240 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcd.sys -- (Nokia USB Phone Parent)
DRV - [2006/10/10 09:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcj.sys -- (Nokia USB Port)
DRV - [2006/10/10 09:54:32 | 000,012,800 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcm.sys -- (Nokia USB Modem)
DRV - [2006/10/10 09:54:32 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdc.sys -- (Nokia USB Generic)
DRV - [2006/06/13 06:20:00 | 000,094,460 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/06/13 06:20:00 | 000,088,476 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/06/13 06:20:00 | 000,086,844 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/06/13 06:20:00 | 000,025,724 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/06/13 06:20:00 | 000,014,716 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/06/13 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/06/13 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\DLADResN.SYS -- (DLADResN)
DRV - [2006/03/17 09:35:24 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/03/17 09:34:46 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2004/12/04 00:34:26 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/11/16 13:03:52 | 000,108,791 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\Apfiltr.sys -- (ApfiltrService)
DRV - [2004/10/21 18:56:04 | 003,210,496 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\w29n51.sys -- (w29n51) Intel(R)
DRV - [2004/10/08 12:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2004/09/21 11:55:20 | 000,084,512 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdm.sys -- (ssm_mdm)
DRV - [2004/09/21 11:55:20 | 000,006,096 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_mdfl.sys -- (ssm_mdfl)
DRV - [2004/09/21 11:55:18 | 000,052,416 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssm_bus.sys -- (ssm_bus) Samsung Mobile USB Device II 1.0 driver (WDM)
DRV - [2004/09/15 22:53:12 | 000,271,704 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\STAC97.sys -- (STAC97)
DRV - [2004/08/31 11:53:04 | 000,011,354 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\s24trans.sys -- (s24trans)
DRV - [2004/08/18 17:53:54 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2004/08/12 11:44:04 | 000,234,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\iwca.sys -- (IWCA)
DRV - [2004/08/04 08:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKNB.SYS -- (NwlnkNb)
DRV - [2004/08/04 08:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKSPX.SYS -- (NwlnkSpx)
DRV - [2004/06/17 18:57:02 | 000,200,064 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWICH.sys -- (HSFHWICH)
DRV - [2004/06/17 18:55:38 | 000,685,056 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys -- (winachsf)
DRV - [2004/06/17 18:55:04 | 001,041,536 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys -- (HSF_DP)
DRV - [2004/05/26 18:18:18 | 000,044,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/02/13 13:46:00 | 000,017,153 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys -- (omci)
DRV - [2002/09/16 18:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001/07/03 16:47:02 | 000,103,792 | ---- | M] (STMicroelectronics                                          ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\STV672.sys -- (STV672)
DRV - [1999/09/10 12:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {FCAB6FDD-5585-425b-95C1-5ED856F3FD08}:5.7
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\@xmlauthor.com/downloads: C:\WINDOWS\system32\npmirage.dll (XMLAuthor Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Basti\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/28 21:48:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/26 10:56:22 | 000,000,000 | ---D | M]
 
[2009/01/17 18:30:51 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Extensions
[2011/06/28 11:53:01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions
[2010/09/29 10:00:43 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/21 15:10:25 | 000,000,000 | ---D | M] (Sothink Web Video Downloader for Firefox) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}
[2010/09/29 10:00:01 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2010/09/29 10:00:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Basti\Application Data\Mozilla\Firefox\Profiles\5c7hazpn.default\extensions\[email protected]
[2011/06/28 11:53:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/08/25 19:10:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2009/12/20 21:30:07 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/07/25 20:47:23 | 000,000,000 | ---D | M] (Orbit Downloader Firefox Integration) -- C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ORBITFF
[2010/07/17 06:00:04 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2011/06/16 20:20:36 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/06/16 20:20:36 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/06/16 20:20:36 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/06/16 20:20:36 | 000,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
 
O1 HOSTS File: ([2011/10/13 18:17:43 | 000,000,027 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (eBay Toolbar Helper) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O2 - BHO: (PaltalkWebLogin) - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll (AVM Software Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\DLASHX_W.DLL (Sonic Solutions)
O3 - HKLM\..\Toolbar: (no name) -  - No CLSID value found.
O3 - HKLM\..\Toolbar: (eBay Toolbar) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ()
O4 - HKLM..\Run: [DLA] C:\WINDOWS\SYSTEM32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Timezone] C:\Program Files\Microsoft Time Zone\TimeZone.exe (Microsoft)
O4 - HKCU..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\Basti\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: eBay Search - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - res://D:\FlashCapture\fciext.dll/FCIEXT.htm File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab (DjVuCtl Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www4.snapfish.com.au/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe (Virtools WebPlayer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{224F3BDC-E16C-483D-9088-91290CED9ABA}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\IntelWireless: DllName - (C:\Program Files\Intel\Wireless\Bin\LgNotify.dll) - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Basti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 16:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/10/17 19:38:57 | 000,000,000 | ---D | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2007/09/28 19:42:02 | 000,002,292 | ---- | M] () - C:\autorun.PNF -- [ NTFS ]
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell - "" = AutoRun
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{1699012c-2a90-11df-aabf-001f81000250}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{17b9818e-b3fb-11dc-a59e-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell - "" = AutoRun
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6149c55d-f7e9-11dc-a658-00114374ee38}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6cdec37a-a26d-11dd-a7fb-0012f04276e6}\Shell\AutoRun\command - "" = G:\setupSNK.exe
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77254c42-a94d-11dc-a588-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486a-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486b-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a133486c-a94b-11dc-a587-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c6df0e2e-5290-11de-a95c-0012f04276e6}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell - "" = AutoRun
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{fc8ae204-ebf8-11df-ab54-0012f04276e6}\Shell\AutoRun\command - "" = G:\NetTV-Stick.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/01/31 18:51:07 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2012/01/31 16:39:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\Start Menu\Programs\HiJackThis
[2012/01/31 15:59:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012/01/22 22:18:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Any Video Converter
[2012/01/22 21:59:27 | 000,414,368 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/01/18 01:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Basti\My Documents\Aimersoft DVD Ripper
[2012/01/18 01:00:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Aimersoft
[2012/01/18 01:00:23 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\WINDOWS\System32\iconv.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/01/31 18:51:20 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Basti\Desktop\OTL.exe
[2012/01/31 18:50:34 | 000,001,554 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2012/01/31 17:39:17 | 000,015,232 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/31 16:13:45 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/01/31 15:52:46 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2012/01/31 15:51:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2012/01/31 15:51:14 | 1073,152,000 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/22 22:28:48 | 000,099,328 | ---- | M] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/22 21:59:27 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/01/18 01:01:44 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/17 18:57:36 | 000,341,032 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/17 18:44:11 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/17 18:32:44 | 000,446,424 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2012/01/17 18:32:44 | 000,073,464 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2012/01/17 17:47:25 | 000,831,743 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:06 | 022,328,992 | ---- | M] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/01/31 17:39:17 | 000,015,232 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\cardscoopon.pdf
[2012/01/31 16:40:08 | 000,000,849 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\HiJackThis.lnk
[2012/01/17 17:47:24 | 000,831,743 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\The_Drive_logo_white bg.jpg
[2012/01/17 17:37:04 | 022,328,992 | ---- | C] () -- C:\Documents and Settings\Basti\Desktop\DCA Video Promo.wmv
[2010/08/26 02:05:48 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\winscp.rnd
[2010/08/07 18:05:27 | 000,073,684 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/06/05 20:50:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/28 16:16:24 | 000,104,182 | ---- | C] () -- C:\WINDOWS\hpoins04.dat
[2009/11/28 16:16:24 | 000,017,176 | ---- | C] () -- C:\WINDOWS\hpomdl04.dat
[2009/05/08 11:13:04 | 000,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 23:39:36 | 000,082,289 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/04/30 17:00:12 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/02/22 15:45:42 | 000,641,021 | ---- | C] () -- C:\WINDOWS\unins000.exe
[2009/02/22 15:45:42 | 000,187,904 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2009/02/22 15:45:42 | 000,166,912 | ---- | C] () -- C:\WINDOWS\System32\Lame_enc.dll
[2009/02/22 15:45:42 | 000,002,890 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2009/01/31 18:51:04 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/28 11:04:01 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/28 11:04:00 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/28 11:03:59 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/27 19:01:25 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/27 19:01:25 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/27 19:01:25 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/27 19:01:25 | 000,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/22 07:09:03 | 000,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/01/17 18:30:53 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2008/10/01 22:41:06 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/10/01 22:41:06 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/10/01 22:41:06 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/10/01 22:41:06 | 000,112,640 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/10/01 18:36:23 | 000,000,074 | -H-- | C] () -- C:\WINDOWS\uce.dat
[2008/07/03 01:43:26 | 000,013,805 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2008/07/03 01:42:59 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/04/30 23:28:31 | 000,408,576 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2008/04/30 23:28:31 | 000,066,560 | ---- | C] () -- C:\WINDOWS\MOTA113.exe
[2008/04/30 23:28:31 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2008/04/30 23:28:30 | 000,502,784 | ---- | C] () -- C:\WINDOWS\x2.64.exe
[2008/04/30 23:28:30 | 000,240,128 | ---- | C] () -- C:\WINDOWS\System32\x.264.exe
[2008/04/30 23:28:30 | 000,217,073 | ---- | C] () -- C:\WINDOWS\meta4.exe
[2008/01/04 08:11:11 | 000,001,359 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/03/13 14:40:54 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\$_hpcst$.hpc
[2007/02/22 11:13:50 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/09/29 18:18:33 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2006/02/27 22:22:36 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CompanionApp.INI
[2006/02/27 22:19:44 | 000,002,508 | ---- | C] () -- C:\Documents and Settings\Basti\Application Data\$_hpcst$.hpc
[2006/01/28 12:31:45 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/10/26 17:03:16 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/10/26 16:59:36 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/08/22 11:16:29 | 000,000,021 | ---- | C] () -- C:\WINDOWS\System32\p.dat
[2005/08/22 11:15:48 | 000,129,822 | ---- | C] () -- C:\WINDOWS\System32\system.dat
[2005/06/18 18:13:39 | 000,099,328 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/05/25 08:32:44 | 000,524,288 | ---- | C] () -- C:\WINDOWS\System32\DivXsm.exe
[2005/05/06 12:36:42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Basti\Local Settings\Application Data\fusioncache.dat
[2005/05/06 12:17:14 | 000,000,300 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2005/05/06 12:16:49 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbcvs.dll
[2005/05/06 12:16:44 | 000,000,373 | ---- | C] () -- C:\WINDOWS\System32\dlbccoin.ini
[2005/05/06 11:51:35 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\instlsp.exe
[2005/05/05 20:52:49 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/04/28 15:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/28 15:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/28 15:22:34 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/04/25 17:05:26 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/04/25 17:03:17 | 000,000,344 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/04/25 16:59:24 | 000,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/04/25 16:45:48 | 000,002,048 | --S- | C] () -- C:\WINDOWS\BOOTSTAT.DAT
[2005/04/25 16:45:06 | 000,446,424 | ---- | C] () -- C:\WINDOWS\System32\PERFH009.DAT
[2005/04/25 16:45:06 | 000,073,464 | ---- | C] () -- C:\WINDOWS\System32\PERFC009.DAT
[2005/04/25 16:36:32 | 000,000,367 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/12/20 11:08:28 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/10/15 21:56:40 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/12 11:44:10 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\iwca.dll
[2004/08/10 16:13:12 | 000,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI
[2004/08/10 16:08:08 | 000,341,032 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 16:03:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/08/10 16:02:16 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 13:08:26 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.BIN
[2004/08/10 13:08:26 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\OEMBIOS.DAT
[2004/08/04 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\MLANG.DAT
[2004/08/04 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\PERFI009.DAT
[2004/08/04 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\DSSEC.DAT
[2004/08/04 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\MIB.BIN
[2004/08/04 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\PERFD009.DAT
[2004/08/04 08:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\SECUPD.DAT
[2004/08/04 08:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 08:00:00 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI
[2004/08/04 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\NOISE.DAT
[2004/07/19 19:01:02 | 000,045,056 | ---- | C] () -- C:\WINDOWS\SETPWRCG.EXE
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1999/07/23 14:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/27 14:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1996/02/24 08:34:48 | 000,014,629 | ---- | C] () -- C:\WINDOWS\System32\Declw.dll
[1996/02/23 06:09:20 | 000,032,256 | ---- | C] () -- C:\WINDOWS\System32\Decln.dll
[1980/01/01 03:00:00 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F

< End of report >





EXTRAS.txt

OTL Extras logfile created on: 31/01/2012 6:52:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0     Folder = C:\Documents and Settings\Basti\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
 
1023.37 Mb Total Physical Memory | 596.16 Mb Available Physical Memory | 58.25% Memory free
2.40 Gb Paging File | 2.00 Gb Available in Paging File | 83.16% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 3.70 Gb Free Space | 10.82% Space Free | Partition Type: NTFS
Drive D: | 40.24 Gb Total Space | 3.00 Gb Free Space | 7.46% Space Free | Partition Type: NTFS
 
Computer Name: D1JD5F1S | User Name: Basti | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Paltalk Messenger\paltalk.exe" = C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:Paltalk Messenger 8.2 -- (AVM Software Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"D:\Vuze\Azureus.exe" = D:\Vuze\Azureus.exe:*:Enabled:Azureus -- (Vuze Inc.)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Senstic\i-Clickr\i-Clickr.exe" = C:\Program Files\Senstic\i-Clickr\i-Clickr.exe:*:Enabled:i-Clickr PC Control -- (Senstic)
"D:\Pinnacle\VideoSpin\Programs\RM.exe" = D:\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager
"D:\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe" = D:\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile
"D:\Pinnacle\VideoSpin\Programs\umi.exe" = D:\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi
"D:\Pinnacle\VideoSpin\Programs\VideoSpin.exe" = D:\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft  Fax Console -- (Microsoft Corporation)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC -- (mIRC Co. Ltd.)
"C:\temp\janinblr\iTunnel\iTunnel.exe" = C:\temp\janinblr\iTunnel\iTunnel.exe:*:Enabled:iTunnel -- ()
"C:\Documents and Settings\Basti\My Documents\Downloads\Iphone\iphone_tunnel.exe" = C:\Documents and Settings\Basti\My Documents\Downloads\Iphone\iphone_tunnel.exe:*:Enabled:iphone_tunnel
"C:\Documents and Settings\Basti\My Documents\Downloads\iTunnel\iTunnel.exe" = C:\Documents and Settings\Basti\My Documents\Downloads\iTunnel\iTunnel.exe:*:Enabled:iTunnel
"C:\Documents and Settings\Basti\My Documents\Downloads\umbrella-4.02.05.exe" = C:\Documents and Settings\Basti\My Documents\Downloads\umbrella-4.02.05.exe:*:Enabled:Umbrella - Save your SHSH!
"C:\Program Files\Logitech\Logitech Vid\Vid.exe" = C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid
"C:\Program Files\Logitech\Vid HD\Vid.exe" = C:\Program Files\Logitech\Vid HD\Vid.exe:*:Enabled:Logitech Vid HD -- (Logitech Inc.)
"C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox

18
Tech Clinic / Please Help! Laptop VERY slow and Firefox not working
« on: January 31, 2012, 12:54:50 AM »
Hi guys, would appreciate if someone could try and help me. My laptop is running extremly slow. It takes about 15 - 20min to boot and for some reason firefox is not working anymore. When I double click the icon nothing happens.
Please find below my HijackThis log.

Thanks in advance


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:54:23 PM, on 31/01/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Microsoft Time Zone\TimeZone.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\QuickTime\QuickTimePlayer.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\HiJackThis\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [AutoLaunch] C:\Program Files\Lavasoft\Ad-Aware\AutoLaunch.exe monthly (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\Basti\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 13357 bytes



19
Tech Clinic / Please Help! Spyware/Virus Infection
« on: January 31, 2009, 06:31:57 PM »
Hi guestolo
Things seem to be running fine, the previous problems have disapeared. Thanks for that.
I did a fresh Hickjack this, please find log below.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:48 AM, on 1/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\HalReader\HalReader.exe
D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\3 Mobile\3 Mobile Broadband\3 Mobile Broadband.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Timezone] "C:\Program Files\Microsoft Time Zone\TimeZone.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = D:\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Ultra Hal Text-to-Speech Reader Startup.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: FlashCapture - {753BBC4B-CC73-4fb8-A5B5-CA09C804C1DD} - D:\FlashCapture\fciext.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1...toUploader5.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w...ntrol_en_US.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.com.au/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.Email Removed.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{86F288A6-0FB3-4F82-B407-44AF60354279}: NameServer = 202.124.68.130 202.124.76.98
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 11546 bytes

20
Tech Clinic / Please Help! Spyware/Virus Infection
« on: January 27, 2009, 10:58:02 PM »
Hi guestolo
I downloaded [color=\"#ff0000\"]OTScanIt2[/color][/url] disabled Avast & Ad-aware and ran it. It worked this time.
I tried to post the logg in here a few times but kept getting error messages. Please find the .txt file in the link below.

http://www.savefile.com/files/1984440

Thanks!!!

Pages: [1] 2